CVE-2021-20167: Command Injection
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20167?
CVE-2021-20167 is a command injection vulnerability in Netgear RAX43 version 1.0.3.96.
How does the command injection vulnerability in Netgear RAX43 version 1.0.3.96 work?
The readycloud cgi application in Netgear RAX43 version 1.0.3.96 is vulnerable to command injection in the name parameter, allowing an attacker to execute arbitrary commands on the affected device.
What is the severity of CVE-2021-20167?
CVE-2021-20167 has a severity rating of high with a CVSS score of 8.
How can I fix the command injection vulnerability in Netgear RAX43 version 1.0.3.96?
Update Netgear RAX43 to a version that has a fix for CVE-2021-20167, if available, or follow any instructions provided by the vendor to mitigate the vulnerability.
Where can I find more information about CVE-2021-20167?
More information about CVE-2021-20167 can be found at the following URL: https://www.tenable.com/security/research/tra-2021-55