Command Injection Vulnerability in NETGEAR WiFi Routers
CVE-2021-29079

9.6CRITICAL

Key Information:

Vendor
Netgear
Vendor
CVE Published:
23 March 2021

Summary

Certain NETGEAR WiFi routers are susceptible to command injection attacks that can be exploited by unauthenticated attackers, allowing them to execute arbitrary commands. This vulnerability impacts specific models including RBK852, RBK853, RBK854, RBR850, and RBS850, all before version 3.2.17.12. It is crucial for users of these devices to apply the necessary updates to mitigate the risk and enhance their network security.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.