CVE-2021-29078: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29078?
CVE-2021-29078 has a medium severity rating due to the potential for command injection vulnerabilities.
How do I fix CVE-2021-29078?
To fix CVE-2021-29078, update your NETGEAR device firmware to version 3.2.17.12 or later.
Which NETGEAR devices are affected by CVE-2021-29078?
CVE-2021-29078 affects NETGEAR RBK852, RBK853, RBK854, RBR850, RBS850, RBK752, RBK753, RBK753S, RBK754, RBR750, and RBS750 prior to firmware version 3.2.17.12.
Who can exploit CVE-2021-29078?
CVE-2021-29078 can be exploited by unauthenticated attackers with network access to the affected devices.
What type of vulnerability is CVE-2021-29078?
CVE-2021-29078 is a command injection vulnerability that allows attackers to execute arbitrary commands.