First published: Sun Dec 26 2021(Updated: )
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.2.74, R9000 before 1.0.5.2, and XR500 before 2.3.2.66.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R7800 firmware | <1.0.2.74 | |
NETGEAR R7800 | ||
Netgear R9000 Firmware | <1.0.5.2 | |
NETGEAR R9000 | ||
Netgear Xr500 Firmware | <2.3.2.66 | |
NETGEAR XR500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45623 is a vulnerability that allows an unauthenticated attacker to execute arbitrary commands on certain NETGEAR devices.
CVE-2021-45623 affects NETGEAR R7800 before firmware version 1.0.2.74, NETGEAR R9000 before firmware version 1.0.5.2, and NETGEAR XR500 before firmware version 2.3.2.66.
CVE-2021-45623 has a severity rating of 9.8 (Critical).
To fix CVE-2021-45623, it is recommended to update the firmware of the affected NETGEAR devices to the latest available version.
More information about CVE-2021-45623 can be found in the Netgear Security Advisory: https://kb.netgear.com/000064449/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-Routers-PSV-2019-0203