PT-2021-6244 · NetGear · Netgear Gs728Tpv2+12
Jasperla
·
Published
2021-12-22
·
Updated
2022-01-10
·
CVE-2021-45556
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR GS108Tv2 versions prior to 5.4.2.36
NETGEAR GS110TPP versions prior to 7.0.7.2
NETGEAR GS110TPv2 versions prior to 5.4.2.36
NETGEAR GS110TPv3 versions prior to 7.0.7.2
NETGEAR GS308T versions prior to 1.0.3.2
NETGEAR GS310TP versions prior to 1.0.3.2
NETGEAR GS724TPP versions prior to 2.0.6.3
NETGEAR GS724TPv2 versions prior to 2.0.6.3
NETGEAR GS728TPPv2 versions prior to 6.0.8.2
NETGEAR GS728TPv2 versions prior to 6.0.8.2
NETGEAR GS752TPP versions prior to 6.0.8.2
NETGEAR GS752TPv2 versions prior to 6.0.8.2
NETGEAR MS510TXM versions prior to 1.0.4.2
NETGEAR MS510TXUP versions prior to 1.0.4.2
Description
The issue is related to command injection by an authenticated user due to the lack of input data sanitization in the embedded software of certain NETGEAR devices. This allows a remote attacker to execute arbitrary commands.
Recommendations
For NETGEAR GS108Tv2 version prior to 5.4.2.36, update to version 5.4.2.36 or later.
For NETGEAR GS110TPP version prior to 7.0.7.2, update to version 7.0.7.2 or later.
For NETGEAR GS110TPv2 version prior to 5.4.2.36, update to version 5.4.2.36 or later.
For NETGEAR GS110TPv3 version prior to 7.0.7.2, update to version 7.0.7.2 or later.
For NETGEAR GS308T version prior to 1.0.3.2, update to version 1.0.3.2 or later.
For NETGEAR GS310TP version prior to 1.0.3.2, update to version 1.0.3.2 or later.
For NETGEAR GS724TPP version prior to 2.0.6.3, update to version 2.0.6.3 or later.
For NETGEAR GS724TPv2 version prior to 2.0.6.3, update to version 2.0.6.3 or later.
For NETGEAR GS728TPPv2 version prior to 6.0.8.2, update to version 6.0.8.2 or later.
For NETGEAR GS728TPv2 version prior to 6.0.8.2, update to version 6.0.8.2 or later.
For NETGEAR GS752TPP version prior to 6.0.8.2, update to version 6.0.8.2 or later.
For NETGEAR GS752TPv2 version prior to 6.0.8.2, update to version 6.0.8.2 or later.
For NETGEAR MS510TXM version prior to 1.0.4.2, update to version 1.0.4.2 or later.
For NETGEAR MS510TXUP version prior to 1.0.4.2, update to version 1.0.4.2 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Gs108Tv2
Netgear Gs110Tpp
Netgear Gs110Tpv2
Netgear Gs110Tpv3
Netgear Gs308T
Netgear Gs310Tp
Netgear Gs724Tpp
Netgear Gs724Tpv2
Netgear Gs728Tpv2
Netgear Gs752Tpp
Netgear Gs752Tpv2
Netgear Ms510Txm
Netgear Ms510Txup