First published: Thu Dec 30 2021(Updated: )
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6700 Firmware | =1.0.4.120 | |
NETGEAR R6700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20173 is a command injection vulnerability in the update functionality of Netgear Nighthawk R6700 version 1.0.4.120.
CVE-2021-20173 can be exploited by triggering a system update check via the SOAP interface, allowing an attacker to inject commands through preconfigured values.
The severity rating of CVE-2021-20173 is high, with a CVSS score of 8.8.
Netgear Nighthawk R6700 version 1.0.4.120 is affected by CVE-2021-20173.
To mitigate CVE-2021-20173, update the firmware of the Netgear Nighthawk R6700 device to a version that does not contain the vulnerability.