First published: Tue Mar 23 2021(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR RBK852 | <3.2.17.12 | |
NETGEAR Orbi RBK852 | ||
NETGEAR RBK853 | <3.2.17.12 | |
NETGEAR Orbi RBK853 | ||
NETGEAR RBK854 | <3.2.17.12 | |
NETGEAR Orbi RBK854 | ||
NETGEAR RBR850 firmware | <3.2.17.12 | |
NETGEAR RBR850 firmware | ||
NETGEAR RBS850 Firmware | <3.2.17.12 | |
NETGEAR RBS850 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29070 has a medium severity rating due to the potential for authenticated command injection on affected NETGEAR devices.
To fix CVE-2021-29070, update to the firmware version 3.2.17.12 or later for the affected NETGEAR devices.
CVE-2021-29070 affects NETGEAR devices including RBK852, RBK853, RBK854, RBR850, and RBS850 prior to firmware version 3.2.17.12.
CVE-2021-29070 requires authentication to exploit, which limits the risk compared to remote vulnerabilities.
A command injection vulnerability allows an attacker to execute arbitrary commands on the device, potentially compromising its security.