CVE-2021-20173

HIGH WAF: High
CVSS 8.8 Published: 2021-12-30
CWE-78

Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
netgearr6700_firmware1.0.4.120

References

Back to CVE Database