CVE-2021-38519: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.0.2.8, R7000 before 1.0.9.88, R6900P before 1.3.2.132, R7100LG before 1.0.0.52, R7900 before 1.0.3.10, R8000 before 1.0.4.46, R7900P before 1.4.1.50, R8000P before 1.4.1.50, and RAX80 before 1.0.1.40.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2021-38519?
The affected devices include R6250, R6300v2, R6400, R6400v2, R6700v3, R6700, R6900, R7000, and R6900P.
What is the severity of CVE-2021-38519?
The severity of CVE-2021-38519 is high with a CVSS base score of 7.2.
How can an authenticated user exploit CVE-2021-38519?
An authenticated user can exploit CVE-2021-38519 through command injection.
What is the recommended fix for CVE-2021-38519?
Update the firmware of the affected NETGEAR devices to versions that are not vulnerable.
Where can I find more information about CVE-2021-38519?
You can find more information about CVE-2021-38519 in the Netgear security advisory linked in the references.