CVE-2021-29077: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-29077?
CVE-2021-29077 is a vulnerability that allows an unauthenticated attacker to execute arbitrary commands on certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2021-29077?
RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12 are affected by CVE-2021-29077.
How severe is CVE-2021-29077?
CVE-2021-29077 has a severity rating of 9.6 out of 10, which is considered critical.
How can I fix CVE-2021-29077?
To fix CVE-2021-29077, you should update the firmware of your affected NETGEAR device to the latest version provided by the manufacturer.
Where can I find more information about CVE-2021-29077?
You can find more information about CVE-2021-29077 in the security advisory published by NETGEAR at the following link: https://kb.netgear.com/000063016/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2020-0486