PT-2021-6273 · NetGear · Netgear Wnr3500Lv2+23
Published
2021-09-25
·
Updated
2022-01-05
·
CVE-2021-45550
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NETGEAR D3600 versions prior to 1.0.0.76
NETGEAR D6000 versions prior to 1.0.0.78
NETGEAR D6100 versions prior to 1.0.0.63
NETGEAR D6220 versions prior to 1.0.0.52
NETGEAR D6400 versions prior to 1.0.0.86
NETGEAR D7800 versions prior to 1.0.1.56
NETGEAR D8500 versions prior to 1.0.3.44
NETGEAR DGN2200Bv4 versions prior to 1.0.0.109
NETGEAR DGN2200v4 versions prior to 1.0.0.110
NETGEAR R6250 versions prior to 1.0.4.34
NETGEAR R6300v2 versions prior to 1.0.4.34
NETGEAR R6400 versions prior to 1.0.1.46
NETGEAR R6400v2 versions prior to 1.0.2.66
NETGEAR R6700 versions prior to 1.0.2.6
NETGEAR R6700v3 versions prior to 1.0.2.66
NETGEAR R6900 versions prior to 1.0.2.4
NETGEAR R6900P versions prior to 1.3.1.64
NETGEAR R7000 versions prior to 1.0.9.42
NETGEAR R7000P versions prior to 1.3.1.64
NETGEAR R7100LG versions prior to 1.0.0.50
NETGEAR R7300 versions prior to 1.0.0.70
NETGEAR R7900 versions prior to 1.0.3.8
NETGEAR R7900P versions prior to 1.4.1.30
NETGEAR R8000 versions prior to 1.0.4.28
NETGEAR R8000P versions prior to 1.4.1.30
NETGEAR R8300 versions prior to 1.0.2.128
NETGEAR R8500 versions prior to 1.0.2.128
NETGEAR WNDR3400v3 versions prior to 1.0.1.24
NETGEAR WNR3500Lv2 versions prior to 1.2.0.62
NETGEAR XR500 versions prior to 2.3.2.56
Description
The issue is related to command injection by an authenticated user due to the lack of input data sanitization. This allows a remote attacker to execute arbitrary commands.
Recommendations
Update NETGEAR D3600 to version 1.0.0.76 or later
Update NETGEAR D6000 to version 1.0.0.78 or later
Update NETGEAR D6100 to version 1.0.0.63 or later
Update NETGEAR D6220 to version 1.0.0.52 or later
Update NETGEAR D6400 to version 1.0.0.86 or later
Update NETGEAR D7800 to version 1.0.1.56 or later
Update NETGEAR D8500 to version 1.0.3.44 or later
Update NETGEAR DGN2200Bv4 to version 1.0.0.109 or later
Update NETGEAR DGN2200v4 to version 1.0.0.110 or later
Update NETGEAR R6250 to version 1.0.4.34 or later
Update NETGEAR R6300v2 to version 1.0.4.34 or later
Update NETGEAR R6400 to version 1.0.1.46 or later
Update NETGEAR R6400v2 to version 1.0.2.66 or later
Update NETGEAR R6700 to version 1.0.2.6 or later
Update NETGEAR R6700v3 to version 1.0.2.66 or later
Update NETGEAR R6900 to version 1.0.2.4 or later
Update NETGEAR R6900P to version 1.3.1.64 or later
Update NETGEAR R7000 to version 1.0.9.42 or later
Update NETGEAR R7000P to version 1.3.1.64 or later
Update NETGEAR R7100LG to version 1.0.0.50 or later
Update NETGEAR R7300 to version 1.0.0.70 or later
Update NETGEAR R7900 to version 1.0.3.8 or later
Update NETGEAR R7900P to version 1.4.1.30 or later
Update NETGEAR R8000 to version 1.0.4.28 or later
Update NETGEAR R8000P to version 1.4.1.30 or later
Update NETGEAR R8300 to version 1.0.2.128 or later
Update NETGEAR R8500 to version 1.0.2.128 or later
Update NETGEAR WNDR3400v3 to version 1.0.1.24 or later
Update NETGEAR WNR3500Lv2 to version 1.2.0.62 or later
Update NETGEAR XR500 to version 2.3.2.56 or later
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear D3600
Netgear D6000
Netgear R6100
Netgear R6220
Netgear R6400
Netgear R7800
Netgear R8500
Netgear Dgn2200V4
Netgear R6250
Netgear R6300V2
Netgear R6400V2
Netgear R6700
Netgear R6700V3
Netgear R6900P
Netgear R7000
Netgear R7000P
Netgear R7100Lg
Netgear R7300
Netgear R7900
Netgear R8000
Netgear R8300
Netgear Wndr3400V3
Netgear Wnr3500Lv2
Netgear Xr500