Command Injection Vulnerability in NETGEAR WiFi Systems
CVE-2021-29077
9.6CRITICAL
Summary
Certain NETGEAR WiFi systems are susceptible to a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands on the affected devices. This flaw affects multiple models, including RBW30, RBS40V, and several iterations of the RBK series, all before specific firmware versions. If exploited, this vulnerability poses a significant risk, enabling potential attackers to gain unauthorized control over the devices, leading to network breaches and compromised user data.
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved