CVE-2021-45580: Command Injection
Published Dec 26, 2021
·Updated
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.
Affected Software
24 affected components
Netgear Rbk752 Firmware<3.2.16.6
Netgear RBK752
Netgear RBR750 firmware<3.2.16.6
Netgear RBR750
Netgear Rbs750 Firmware<3.2.16.6
Netgear RBS750
Netgear Rbk852 Firmware<3.2.16.6
Netgear RBK852
Netgear Rbr850 Firmware<3.2.16.6
Netgear RBR850
Netgear Rbs850 Firmware<3.2.16.6
Netgear RBS850
All of the following
Netgear Rbk752 Firmware<3.2.16.6
Netgear RBK752
All of the following
Netgear RBR750 firmware<3.2.16.6
Netgear RBR750
All of the following
Netgear Rbs750 Firmware<3.2.16.6
Netgear RBS750
All of the following
Netgear Rbk852 Firmware<3.2.16.6
Netgear RBK852
All of the following
Netgear Rbr850 Firmware<3.2.16.6
Netgear RBR850
All of the following
Netgear Rbs850 Firmware<3.2.16.6
Netgear RBS850
Event History
Dec 26, 2021
CVE Published
via MITRE·12:43 AM
Data Sourced
via MITRE·12:43 AM
DescriptionSeverity
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-45580?
CVE-2021-45580 is a vulnerability that allows command injection by an authenticated user on certain NETGEAR devices.
2
Which NETGEAR devices are affected by CVE-2021-45580?
RBK752, RBR750, RBS750, RBK852, RBR850, and RBS850 devices are affected by CVE-2021-45580.
3
What is the severity of CVE-2021-45580?
The severity of CVE-2021-45580 is high with a CVSS score of 6.8.
4
How can an authenticated user exploit CVE-2021-45580?
An authenticated user can exploit CVE-2021-45580 by injecting commands into the affected NETGEAR devices.
5
How can I fix CVE-2021-45580?
To fix CVE-2021-45580, update the firmware of the affected NETGEAR devices to version 3.2.16.6 or later.