| Vulnerability Name: | CCN-210216 | ||||||||||||
| Published: | 2021-09-26 | ||||||||||||
| Updated: | 2021-09-26 | ||||||||||||
| Summary: | Multiple NETGEAR Routers and WiFi Systems could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. | ||||||||||||
| CVSS v3 Severity: | 8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) 7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.7 High (CCN CVSS v2 Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: XF Type: UNKNOWN netgear-psv20200053-cmd-exec(210216) Source: CCN Type: NETGEAR Security Advisory: PSV-2020-0053 Security Advisory for Post-Authentication Command Injection on Some WiFi Systems | ||||||||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Vulnerability Name: | CVE-2021-45558 (CCN-210216) | ||||||||||||
| Assigned: | 2021-09-26 | ||||||||||||
| Published: | 2021-09-26 | ||||||||||||
| Updated: | 2022-01-04 | ||||||||||||
| Summary: | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6. | ||||||||||||
| CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.2 Medium (CVSS v2 Vector: AV:A/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-77 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: XF Type: UNKNOWN netgear-psv20200053-cmd-exec(210216) Source: CCN Type: NETGEAR Security Advisory: PSV-2020-0053 Security Advisory for Post-Authentication Command Injection on Some WiFi Systems | ||||||||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||