CVE-2021-45632: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45632?
CVE-2021-45632 is a vulnerability that affects certain NETGEAR devices, allowing an unauthenticated attacker to execute arbitrary commands.
Which NETGEAR devices are affected by CVE-2021-45632?
The following NETGEAR devices are affected by CVE-2021-45632: CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
What is the severity of CVE-2021-45632?
CVE-2021-45632 has a severity level of 8.8, which is considered critical.
How does CVE-2021-45632 work?
CVE-2021-45632 allows an unauthenticated attacker to inject and execute arbitrary commands on affected NETGEAR devices.
Is there a fix for CVE-2021-45632?
Yes, the fix for CVE-2021-45632 is to update the firmware of the affected NETGEAR devices to versions higher than the vulnerable ones listed: CBR750 firmware version 4.6.3.6 or higher, RBK752 firmware version 3.2.17.12 or higher, RBR750 firmware version 3.2.17.12 or higher, RBS750 firmware version 3.2.17.12 or higher, RBK852 firmware version 3.2.17.12 or higher, RBR850 firmware version 3.2.17.12 or higher, and RBS850 firmware version 3.2.17.12 or higher.