First published: Tue Mar 23 2021(Updated: )
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Rbw30 Firmware | <2.6.2.2 | |
Netgear Rbw30 | ||
Netgear Rbs40v Firmware | <2.6.2.4 | |
Netgear Rbs40v | ||
Netgear Rbk852 Firmware | <3.2.17.12 | |
Netgear Rbk852 | ||
Netgear Rbk853 Firmware | <3.2.17.12 | |
Netgear Rbk853 | ||
Netgear Rbk854 Firmware | <3.2.17.12 | |
Netgear Rbk854 | ||
Netgear Rbr850 Firmware | <3.2.17.12 | |
NETGEAR RBR850 | ||
Netgear Rbs850 Firmware | <3.2.17.12 | |
Netgear Rbs850 | ||
Netgear Rbk752 Firmware | <3.2.17.12 | |
Netgear Rbk752 | ||
Netgear Rbk753 Firmware | <3.2.17.12 | |
Netgear Rbk753 | ||
Netgear Rbk753s Firmware | <3.2.17.12 | |
Netgear Rbk753s | ||
Netgear Rbk754 Firmware | <3.2.17.12 | |
Netgear Rbk754 | ||
Netgear Rbr750 Firmware | <3.2.17.12 | |
Netgear Rbr750 | ||
Netgear Rbs750 Firmware | <3.2.17.12 | |
Netgear Rbs750 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29077 is a vulnerability that allows an unauthenticated attacker to execute arbitrary commands on certain NETGEAR devices.
RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12 are affected by CVE-2021-29077.
CVE-2021-29077 has a severity rating of 9.6 out of 10, which is considered critical.
To fix CVE-2021-29077, you should update the firmware of your affected NETGEAR device to the latest version provided by the manufacturer.
You can find more information about CVE-2021-29077 in the security advisory published by NETGEAR at the following link: https://kb.netgear.com/000063016/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2020-0486