Command Injection Vulnerability in NETGEAR Switches
CVE-2021-45557

7.5HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Certain NETGEAR devices are susceptible to command injection vulnerabilities that can be exploited by authenticated users. This flaw affects various models of NETGEAR switches, allowing attackers to execute arbitrary commands within the device's operating environment. This could lead to unauthorized control and manipulation of system settings, potentially compromising network security.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.