CVE-2021-41383: Command Injection
setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntpserver field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41383?
CVE-2021-41383 is a vulnerability found in NETGEAR R6020 1.0.0.48 devices that allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.
How severe is CVE-2021-41383?
CVE-2021-41383 has a severity level of 7.2 (critical).
How can an admin execute arbitrary shell commands in CVE-2021-41383?
An admin can execute arbitrary shell commands in CVE-2021-41383 by using shell metacharacters in the ntp_server field.
Which devices are affected by CVE-2021-41383?
NETGEAR R6020 1.0.0.48 devices are affected by CVE-2021-41383.
Is NETGEAR R6020 vulnerable to CVE-2021-41383?
Yes, NETGEAR R6020 devices with firmware version 1.0.0.48 are vulnerable to CVE-2021-41383.
How can I fix CVE-2021-41383?
To fix CVE-2021-41383, update the firmware of your NETGEAR R6020 device to a version that addresses the vulnerability.