CVE-2021-45627: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45627?
CVE-2021-45627 refers to a command injection vulnerability in certain NETGEAR devices.
Which NETGEAR devices are affected by CVE-2021-45627?
CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12 are affected.
How severe is CVE-2021-45627?
CVE-2021-45627 has a severity rating of 9.8 (critical).
How can I fix CVE-2021-45627?
To fix CVE-2021-45627, update the firmware of affected NETGEAR devices to versions higher than the vulnerable ones.
Where can I find more information about CVE-2021-45627?
More information about CVE-2021-45627 can be found in the Netgear knowledge base article at: https://kb.netgear.com/000064124/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2020-0471