CVE-2021-29076: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-29076?
CVE-2021-29076 is a vulnerability that affects certain NETGEAR devices, allowing an unauthenticated attacker to perform command injection.
Which devices are affected by CVE-2021-29076?
RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12 are affected by CVE-2021-29076.
What is the severity of CVE-2021-29076?
CVE-2021-29076 has a severity rating of 9.6 (Critical).
How can an unauthenticated attacker exploit CVE-2021-29076?
An unauthenticated attacker can exploit CVE-2021-29076 by performing command injection.
Is there a fix available for CVE-2021-29076?
Yes, the fix for CVE-2021-29076 is to upgrade RBK852, RBK853, RBK854, RBR850, and RBS850 to version 3.2.17.12 or later.