CVE-2021-45623: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.2.74, R9000 before 1.0.5.2, and XR500 before 2.3.2.66.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45623?
CVE-2021-45623 is a vulnerability that allows an unauthenticated attacker to execute arbitrary commands on certain NETGEAR devices.
Which devices are affected by CVE-2021-45623?
CVE-2021-45623 affects NETGEAR R7800 before firmware version 1.0.2.74, NETGEAR R9000 before firmware version 1.0.5.2, and NETGEAR XR500 before firmware version 2.3.2.66.
How severe is CVE-2021-45623?
CVE-2021-45623 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-45623?
To fix CVE-2021-45623, it is recommended to update the firmware of the affected NETGEAR devices to the latest available version.
Where can I find more information about CVE-2021-45623?
More information about CVE-2021-45623 can be found in the Netgear Security Advisory: https://kb.netgear.com/000064449/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-Routers-PSV-2019-0203