First published: Thu Dec 30 2021(Updated: )
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Rax43 Firmware | =1.0.3.96 | |
Netgear RAX43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20167 is a command injection vulnerability in Netgear RAX43 version 1.0.3.96.
The readycloud cgi application in Netgear RAX43 version 1.0.3.96 is vulnerable to command injection in the name parameter, allowing an attacker to execute arbitrary commands on the affected device.
CVE-2021-20167 has a severity rating of high with a CVSS score of 8.
Update Netgear RAX43 to a version that has a fix for CVE-2021-20167, if available, or follow any instructions provided by the vendor to mitigate the vulnerability.
More information about CVE-2021-20167 can be found at the following URL: https://www.tenable.com/security/research/tra-2021-55