CVE-2021-45552: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.108, and XR700 before 1.0.1.20.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45552?
CVE-2021-45552 is a vulnerability that allows an authenticated user to perform command injection on certain NETGEAR devices.
Which devices are affected by CVE-2021-45552?
CVE-2021-45552 affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.108, and XR700 before 1.0.1.20.
What is the severity of CVE-2021-45552?
CVE-2021-45552 has a severity of 7.2 (High).
How can an authenticated user exploit CVE-2021-45552?
An authenticated user can exploit CVE-2021-45552 by injecting and executing arbitrary commands.
How can I fix CVE-2021-45552?
To fix CVE-2021-45552, ensure you are running the latest firmware version for your NETGEAR device.