CVE-2021-45535: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.3.106, RAX80 before 1.0.3.106, RAX75 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID for this command injection vulnerability is CVE-2021-45535.
Which NETGEAR devices are affected by this command injection vulnerability?
This command injection vulnerability affects RAX200 before 1.0.3.106, RAX80 before 1.0.3.106, RAX75 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850.
What is the severity of CVE-2021-45535?
The severity of CVE-2021-45535 is high with a CVSS score of 6.8.
How can I fix the command injection vulnerability in the affected NETGEAR devices?
To fix the command injection vulnerability, update the firmware of the affected NETGEAR devices to the specified versions: RAX200 - 1.0.3.106, RAX80 - 1.0.3.106, RAX75 - 1.0.3.106, RBK752 - 3.2.16.6, RBR750 - 3.2.16.6, RBS750 - 3.2.16.6, RBK852 - 3.2.16.6, RBR850 - 3.2.16.6, and RBS850 - 3.2.16.6.
Where can I find more information about the CVE-2021-45535 vulnerability?
You can find more information about the CVE-2021-45535 vulnerability in the Netgear Security Advisory: https://kb.netgear.com/000064457/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-WiFi-Systems-PSV-2020-0052