CVE-2021-38520: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by command injection?
Certain NETGEAR devices are affected by command injection, including R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.
What is the severity of CVE-2021-38520?
The severity of CVE-2021-38520 is high with a CVSS score of 7.2.
How does the command injection vulnerability work?
The command injection vulnerability in certain NETGEAR devices allows an authenticated user to execute arbitrary commands on the device.
How can I fix CVE-2021-38520?
To fix CVE-2021-38520, update your NETGEAR device firmware to the specified versions: R6400 - 1.0.1.52, R6400v2 - 1.0.4.84, R6700v3 - 1.0.4.84, R6700v2 - 1.2.0.62, R6900v2 - 1.2.0.62, and R7000P - 1.3.2.124.
Where can I find more information about CVE-2021-38520?
You can find more information about CVE-2021-38520 at the following reference link: [https://kb.netgear.com/000063763/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2018-0565](https://kb.netgear.com/000063763/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2018-0565)