PT-2021-6244 · NetGear · Netgear Gs728Tpv2+12

Jasperla

·

Published

2021-12-22

·

Updated

2022-01-10

·

CVE-2021-45556

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR GS108Tv2 versions prior to 5.4.2.36 NETGEAR GS110TPP versions prior to 7.0.7.2 NETGEAR GS110TPv2 versions prior to 5.4.2.36 NETGEAR GS110TPv3 versions prior to 7.0.7.2 NETGEAR GS308T versions prior to 1.0.3.2 NETGEAR GS310TP versions prior to 1.0.3.2 NETGEAR GS724TPP versions prior to 2.0.6.3 NETGEAR GS724TPv2 versions prior to 2.0.6.3 NETGEAR GS728TPPv2 versions prior to 6.0.8.2 NETGEAR GS728TPv2 versions prior to 6.0.8.2 NETGEAR GS752TPP versions prior to 6.0.8.2 NETGEAR GS752TPv2 versions prior to 6.0.8.2 NETGEAR MS510TXM versions prior to 1.0.4.2 NETGEAR MS510TXUP versions prior to 1.0.4.2
Description The issue is related to command injection by an authenticated user due to the lack of input data sanitization in the embedded software of certain NETGEAR devices. This allows a remote attacker to execute arbitrary commands.
Recommendations For NETGEAR GS108Tv2 version prior to 5.4.2.36, update to version 5.4.2.36 or later. For NETGEAR GS110TPP version prior to 7.0.7.2, update to version 7.0.7.2 or later. For NETGEAR GS110TPv2 version prior to 5.4.2.36, update to version 5.4.2.36 or later. For NETGEAR GS110TPv3 version prior to 7.0.7.2, update to version 7.0.7.2 or later. For NETGEAR GS308T version prior to 1.0.3.2, update to version 1.0.3.2 or later. For NETGEAR GS310TP version prior to 1.0.3.2, update to version 1.0.3.2 or later. For NETGEAR GS724TPP version prior to 2.0.6.3, update to version 2.0.6.3 or later. For NETGEAR GS724TPv2 version prior to 2.0.6.3, update to version 2.0.6.3 or later. For NETGEAR GS728TPPv2 version prior to 6.0.8.2, update to version 6.0.8.2 or later. For NETGEAR GS728TPv2 version prior to 6.0.8.2, update to version 6.0.8.2 or later. For NETGEAR GS752TPP version prior to 6.0.8.2, update to version 6.0.8.2 or later. For NETGEAR GS752TPv2 version prior to 6.0.8.2, update to version 6.0.8.2 or later. For NETGEAR MS510TXM version prior to 1.0.4.2, update to version 1.0.4.2 or later. For NETGEAR MS510TXUP version prior to 1.0.4.2, update to version 1.0.4.2 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01175
CVE-2021-45556

Affected Products

Netgear Gs108Tv2
Netgear Gs110Tpp
Netgear Gs110Tpv2
Netgear Gs110Tpv3
Netgear Gs308T
Netgear Gs310Tp
Netgear Gs724Tpp
Netgear Gs724Tpv2
Netgear Gs728Tpv2
Netgear Gs752Tpp
Netgear Gs752Tpv2
Netgear Ms510Txm
Netgear Ms510Txup