Command Injection Vulnerability in NETGEAR Routers
CVE-2021-45623

8.3HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

A command injection vulnerability exists in certain NETGEAR routers that allows unauthenticated attackers to execute arbitrary commands. Devices affected include R7800 before version 1.0.2.74, R9000 before version 1.0.5.2, and XR500 prior to version 2.3.2.66. Proper updates are necessary to mitigate the risk of unauthorized access and control.

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.