Vulnerability Name:
CCN-223418
Published:
2022-03-31
Updated:
2022-03-31
Summary:
NETGEAR devices could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. An attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS v3 Severity:
8.4 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
)
7.3 High
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Adjacent
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
7.7 High
(CCN CVSS v2 Vector:
AV:A/AC:L/Au:S/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Adjacent_Network
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Consequences:
Gain Access
References:
Source: XF
Type: UNKNOWN
netgear-psv20200545-cmd-exec(223418)
Source: CCN
Type: NETGEAR Security Advisory: PSV-2020-0545
Security Advisory for Post-Authentication Command Injection on Some Routers and WiFi Systems
Vulnerable Configuration:
Configuration CCN 1
:
cpe:/h:netgear:r7000p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ex6130:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:dgn2200:v4:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r8000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r6400:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r6400:v2:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbk852:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbr850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mk62:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ms60:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:cbr40:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ex7000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7850:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7900:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r7960p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax200:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax75:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rax80:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rs400:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbw30:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:rbs40v:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:eax20:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:eax80:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ex7500:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:mr60:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ex3700:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:ex6120:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:r8000p:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:xr1000:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:cbr750:-:*:*:*:*:*:*:*
OR
cpe:/h:netgear:lax20:-:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
netgear
r7000p -
netgear
ex6130 -
netgear
dgn2200 v4
netgear
r8000 -
netgear
r6400 -
netgear
r6400 v2
netgear
rbk852 -
netgear
rbr850 -
netgear
rbs850 -
netgear
mk62 -
netgear
ms60 -
netgear
cbr40 -
netgear
ex7000 -
netgear
r7000 -
netgear
r7850 -
netgear
r7900 -
netgear
r7960p -
netgear
rax200 -
netgear
rax75 -
netgear
rax80 -
netgear
rs400 -
netgear
rbw30 -
netgear
rbs40v -
netgear
eax20 -
netgear
eax80 -
netgear
ex7500 -
netgear
mr60 -
netgear
ex3700 -
netgear
ex6120 -
netgear
r8000p -
netgear
xr1000 -
netgear
cbr750 -
netgear
lax20 -