First published: Tue Mar 23 2021(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR RBK852 | <3.2.17.12 | |
NETGEAR RBK852 | ||
NETGEAR RBK853 | <3.2.17.12 | |
NETGEAR RBK853 | ||
NETGEAR RBK854 | <3.2.17.12 | |
NETGEAR RBK854 firmware | ||
NETGEAR RBR850 firmware | <3.2.17.12 | |
NETGEAR RBR850 firmware | ||
NETGEAR RBS850 | <3.2.17.12 | |
NETGEAR RBS850 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29072 has a high severity rating due to the command injection vulnerability present in multiple NETGEAR devices.
To fix CVE-2021-29072, update your NETGEAR device firmware to version 3.2.17.12 or later.
CVE-2021-29072 affects NETGEAR RBK852, RBK853, RBK854, RBR850, and RBS850 devices running firmware versions prior to 3.2.17.12.
CVE-2021-29072 requires authentication for exploitation, making it an authenticated command injection vulnerability.
CVE-2021-29072 may allow an authenticated attacker to execute arbitrary commands on the affected NETGEAR devices.