CVE-2021-45660: High severity netgear rbk40 satellite firmware vulnerability
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45660?
CVE-2021-45660 is a vulnerability affecting certain NETGEAR devices that allows for server-side injection.
Which NETGEAR devices are affected by CVE-2021-45660?
CVE-2021-45660 affects RBK40, RBR40, RBS40, RBK20, RBR20, RBS20, RBK50, RBR50, RBS50, and RBS50Y devices before firmware version 2.5.1.16.
What is the severity of CVE-2021-45660?
CVE-2021-45660 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2021-45660?
To fix CVE-2021-45660, update your NETGEAR device firmware to version 2.5.1.16 or later.
Where can I find more information about CVE-2021-45660?
You can find more information about CVE-2021-45660 in the security advisory published by NETGEAR: https://kb.netgear.com/000064064/Security-Advisory-for-Server-Side-Injection-on-Some-WiFi-Systems-PSV-2019-0133