First published: Sun Dec 26 2021(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R6900P before 1.3.2.126, and R7000P before 1.3.2.126.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R7000 Firmware | <1.0.11.126 | |
NETGEAR R7000 | ||
Netgear R6900p Firmware | <1.3.2.126 | |
Netgear R6900P | ||
Netgear R7000p Firmware | <1.3.2.126 | |
Netgear R7000P | ||
All of | ||
Netgear R7000 Firmware | <1.0.11.126 | |
NETGEAR R7000 | ||
All of | ||
Netgear R6900p Firmware | <1.3.2.126 | |
Netgear R6900P | ||
All of | ||
Netgear R7000p Firmware | <1.3.2.126 | |
Netgear R7000P |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45553 is a command injection vulnerability affecting certain NETGEAR devices.
CVE-2021-45553 affects R7000 before 1.0.11.126, R6900P before 1.3.2.126, and R7000P before 1.3.2.126.
CVE-2021-45553 has a severity rating of 8.8 (high).
To fix CVE-2021-45553, update your NETGEAR device's firmware to version 1.0.11.126 (for R7000) or 1.3.2.126 (for R6900P and R7000P).
You can find more information about CVE-2021-45553 in the Netgear security advisory located at https://kb.netgear.com/000064074/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2019-0225.