CVE-2021-45615

HIGH WAF: High
CVSS 8.8 Published: 2021-12-26
CWE-77

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, R8300 before 1.0.2.154, R8500 before 1.0.2.154, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
netgearcbr40_firmwareup to 2.5.0.24
netgearcbr750_firmwareup to 4.6.3.6
netgearr7900p_firmwareup to 1.4.2.84
netgearr7960p_firmwareup to 1.4.2.84
netgearr8000p_firmwareup to 1.4.2.84
netgearr8300_firmwareup to 1.0.2.154
netgearr8500_firmwareup to 1.0.2.154
netgearrbk752_firmwareup to 3.2.17.12
netgearrbk852_firmwareup to 3.2.17.12
netgearrbr750_firmwareup to 3.2.17.12

References

Back to CVE Database