CVE-2021-45614: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116, RAX15 before 1.0.3.96, RAX20 before 1.0.3.96, RAX200 before 1.0.4.120, RAX45 before 1.0.3.96, RAX50 before 1.0.3.96, RAX43 before 1.0.3.96, RAX40v2 before 1.0.3.96, RAX35v2 before 1.0.3.96, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, and XR1000 before 1.0.0.58.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-45614?
CVE-2021-45614 is a vulnerability that allows an unauthenticated attacker to execute arbitrary commands on certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2021-45614?
The affected devices include D7000v2, LAX20, MK62, MR60, MS60, RAX15, RAX20, RAX200, RAX45, RAX50, RAX43, RAX40v2, RAX35v2, RAX75, RAX80, RBK752, RBR750, RBS750, RBK852, RBR850, and RBS850.
What is the severity of CVE-2021-45614?
CVE-2021-45614 has a severity rating of 9.8, which is classified as critical.
How can an unauthenticated attacker exploit CVE-2021-45614?
An unauthenticated attacker can exploit CVE-2021-45614 by sending crafted requests that contain malicious commands, which are executed on the vulnerable NETGEAR devices.
Is there a fix for CVE-2021-45614?
Yes, NETGEAR has released firmware updates to address the CVE-2021-45614 vulnerability. It is recommended to update the firmware of the affected devices to the latest available version.