CVE-2021-45623

CRITICAL WAF: High
CVSS 9.8 Published: 2021-12-26
CWE-77

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.2.74, R9000 before 1.0.5.2, and XR500 before 2.3.2.66.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
netgearr7800_firmwareup to 1.0.2.74
netgearr9000_firmwareup to 1.0.5.2
netgearxr500_firmwareup to 2.3.2.66

References

Back to CVE Database