CVE-2021-45633: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBR750 before 3.2.17.12, RBR850 before 3.2.17.12, RBS750 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, and RBK852 before 3.2.17.12.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45633?
CVE-2021-45633 is a vulnerability that allows an unauthenticated attacker to perform command injection on certain NETGEAR devices.
How does CVE-2021-45633 affect NETGEAR devices?
CVE-2021-45633 affects NETGEAR devices CBR750 before 4.6.3.6, RBR750 before 3.2.17.12, RBR850 before 3.2.17.12, RBS750 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, and RBK852 before 3.2.17.12.
What is the severity of CVE-2021-45633?
CVE-2021-45633 has a severity score of 8.8 (Critical).
How can I fix CVE-2021-45633?
To fix CVE-2021-45633, update your NETGEAR device firmware to version CBR750 4.6.3.6, RBR750 3.2.17.12, RBR850 3.2.17.12, RBS750 3.2.17.12, RBS850 3.2.17.12, RBK752 3.2.17.12, or RBK852 3.2.17.12.
Where can I find more information about CVE-2021-45633?
You can find more information about CVE-2021-45633 on the NETGEAR security advisory page: https://kb.netgear.com/000064511/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2020-0514