First published: Sun Dec 26 2021(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, and RBS850 before 3.2.17.12.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Cbr40 Firmware | <2.5.0.24 | |
Netgear Cbr40 | ||
Netgear Cbr750 Firmware | <4.6.3.6 | |
Netgear Cbr750 | ||
Netgear Rbr850 Firmware | <3.2.17.12 | |
NETGEAR RBR850 | ||
Netgear Rbs850 Firmware | <3.2.17.12 | |
Netgear Rbs850 | ||
Netgear Rbk852 Firmware | <3.2.17.12 | |
Netgear Rbk852 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45597 is a vulnerability that affects certain NETGEAR devices, allowing authenticated users to execute arbitrary commands.
CVE-2021-45597 affects NETGEAR CBR40, CBR750, RBR850, RBS850, and RBK852 devices.
CVE-2021-45597 has a high severity rating with a CVSS score of 8.8.
An authenticated user can exploit CVE-2021-45597 by injecting and executing arbitrary commands.
To fix CVE-2021-45597, update the firmware of the affected NETGEAR devices to the recommended versions provided by NETGEAR.