CVE-2021-45539: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1.0.4.74, R8000P before 1.4.2.84, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.28, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.28, and RAX75 before 1.0.3.106.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-45539?
The severity of CVE-2021-45539 is high.
Which NETGEAR devices are affected by CVE-2021-45539?
NETGEAR devices affected by CVE-2021-45539 include R7900P, R7960P, R8000, R8000P, MR60, RAX20, RAX45, RAX80, and MS60.
What is the recommended firmware version to fix CVE-2021-45539?
The recommended firmware versions to fix CVE-2021-45539 are R7900P 1.4.2.84, R7960P 1.4.2.84, R8000 1.0.4.74, R8000P 1.4.2.84, MR60 1.0.6.110, RAX20 1.0.2.82, RAX45 1.0.2.28, RAX80 1.0.3.106, and MS60 1.0.6.110.
How can an authenticated user exploit CVE-2021-45539?
An authenticated user can exploit CVE-2021-45539 through command injection.
Where can I find more information about CVE-2021-45539?
More information about CVE-2021-45539 can be found at the following URL: [https://kb.netgear.com/000064476/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-WiFi-Systems-PSV-2020-0195](https://kb.netgear.com/000064476/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-WiFi-Systems-PSV-2020-0195)