CVE-2021-45626: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK20 before 2.6.1.36, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.36, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, and RBS50Y before 2.6.1.40.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45626?
CVE-2021-45626 is a vulnerability that affects certain NETGEAR devices, allowing an unauthenticated attacker to perform command injection.
Which devices are affected by CVE-2021-45626?
RBK20 before 2.6.1.36, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.36, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, and RBS50Y before 2.6.1.40 are affected.
What is the severity of CVE-2021-45626?
CVE-2021-45626 has a severity rating of 8.8 (critical).
How can an attacker exploit CVE-2021-45626?
An unauthenticated attacker can exploit CVE-2021-45626 by performing command injection attacks.
Is there a fix available for CVE-2021-45626?
Yes, a fix is available for CVE-2021-45626. It is recommended to update the affected devices to the latest firmware versions.