CVE-2021-45659: High severity netgear rbk40 satellite firmware vulnerability
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which devices are affected by CVE-2021-45659?
RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40
What is the severity of CVE-2021-45659?
The severity of CVE-2021-45659 is high with a CVSS score of 7.8.
What is the fix for CVE-2021-45659?
Upgrade affected devices to firmware version 2.5.1.16 (for RBK40, RBR40, RBS40, RBK20, RBR20, RBS20, RBK50, RBR50, and RBS50) or version 2.6.1.40 (for RBS50Y).
Where can I find more information about CVE-2021-45659?
You can find more information about CVE-2021-45659 in the Netgear Security Advisory at https://kb.netgear.com/000064063/Security-Advisory-for-Server-Side-Injection-on-Some-WiFi-Systems-PSV-2019-0126.