CVE-2021-38528: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 before 1.0.3.56.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38528?
CVE-2021-38528 is a vulnerability that affects certain NETGEAR devices, allowing unauthenticated attackers to execute commands.
Which NETGEAR devices are affected by CVE-2021-38528?
NETGEAR devices D8500 (before 1.0.3.58), R6900P (before 1.3.2.132), R7000P (before 1.3.2.132), R7100LG (before 1.0.0.64), WNDR3400v3 (before 1.0.1.38), and XR300 (before 1.0.3.56) are affected by CVE-2021-38528.
What is the severity level of CVE-2021-38528?
CVE-2021-38528 has a severity level of 9.8 (Critical).
How can an unauthenticated attacker exploit CVE-2021-38528?
An unauthenticated attacker can exploit CVE-2021-38528 by injecting malicious commands into certain NETGEAR devices.
Is there a fix available for CVE-2021-38528?
Yes, NETGEAR has released firmware updates to address and mitigate the CVE-2021-38528 vulnerability.