CVE-2021-45628: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBS40V before 2.6.2.4, and RBW30 before 2.6.2.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45628?
CVE-2021-45628 is a vulnerability that allows command injection by an unauthenticated attacker on certain NETGEAR devices.
Which devices are affected by CVE-2021-45628?
CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12.
How severe is CVE-2021-45628?
CVE-2021-45628 has a severity rating of 8.8 (critical).
How can I fix CVE-2021-45628?
To fix CVE-2021-45628, update your NETGEAR device to the specified firmware versions indicated in the advisory.
Where can I find more information about CVE-2021-45628?
You can find more information about CVE-2021-45628 in the Netgear Security Advisory.