CVE-2021-45533

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66, EX6130 before 1.0.0.46, EX7000 before 1.0.1.106, EX7500 before 1.0.1.76, EX3700 before 1.0.0.94, EX3800 before 1.0.0.94, RBR850 before 4.6.3.9, RBS850 before 4.6.3.9, and RBK852 before 4.6.3.9.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:ex6120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6120:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:ex6130_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6130:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ex7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex7000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:ex7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex7500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:ex3700_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3700:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:ex3800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex3800:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr850:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs850:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rbk852_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk852:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:32

Type Values Removed Values Added
CVSS v2 : 5.2
v3 : 6.8
v2 : 5.2
v3 : 8.4
References () https://kb.netgear.com/000064458/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Extenders-and-WiFi-Systems-PSV-2020-0062 - Vendor Advisory () https://kb.netgear.com/000064458/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Extenders-and-WiFi-Systems-PSV-2020-0062 - Vendor Advisory

Information

Published : 2021-12-26 01:15

Updated : 2024-11-21 06:32


NVD link : CVE-2021-45533

Mitre link : CVE-2021-45533

CVE.ORG link : CVE-2021-45533


JSON object : View

Products Affected

netgear

  • ex6120_firmware
  • ex3700
  • ex7500
  • rbs850
  • ex7000_firmware
  • rbk852_firmware
  • ex6120
  • ex6130_firmware
  • ex7000
  • ex3700_firmware
  • ex7500_firmware
  • ex3800_firmware
  • rbr850_firmware
  • ex3800
  • rbr850
  • ex6130
  • rbs850_firmware
  • rbk852
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')