CVE-2021-45587: Command Injection
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-45587.
Which NETGEAR devices are affected by this vulnerability?
This vulnerability affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.
What is the severity of CVE-2021-45587?
The severity of CVE-2021-45587 is high with a CVSS score of 6.8.
How does this vulnerability impact affected devices?
This vulnerability allows an authenticated user to execute arbitrary commands on the affected NETGEAR devices.
How can I fix CVE-2021-45587?
To fix CVE-2021-45587, update the firmware of RBK752, RBR750, RBS750, RBK852, RBR850, and RBS850 to version 3.2.16.6 or later.