Arbitrary Command Execution Vulnerability in NETGEAR R6020
CVE-2021-41383
7.2HIGH
What is CVE-2021-41383?
The setup.cgi script on NETGEAR R6020 devices version 1.0.0.48 is vulnerable to arbitrary command execution. An authenticated administrator can exploit this vulnerability by injecting shell metacharacters into the ntp_server input field, allowing them to execute unrestricted shell commands on the underlying system. This can lead to potential unauthorized access or control over the device, posing significant security risks.