Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.0.2.8, R7000 before 1.0.9.88, R6900P before 1.3.2.132, R7100LG before 1.0.0.52, R7900 before 1.0.3.10, R8000 before 1.0.4.46, R7900P before 1.4.1.50, R8000P before 1.4.1.50, and RAX80 before 1.0.1.40.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
History
19 Aug 2021, 11:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:netgear:r6900:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7100lg_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6250:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6900p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7900_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:rax80:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7900:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7900p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6250_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6300_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6300:v2:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:* cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7100lg:-:*:*:*:*:*:*:* |
|
References | (MISC) https://kb.netgear.com/000063762/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2018-0564 - Vendor Advisory | |
CWE | CWE-77 | |
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 7.2 |
11 Aug 2021, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-11 00:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-38519
Mitre link : CVE-2021-38519
CVE.ORG link : CVE-2021-38519
JSON object : View
Products Affected
netgear
- r6700_firmware
- r7900_firmware
- r6300_firmware
- r6900_firmware
- rax80
- r7900
- r7000
- r6250_firmware
- r6900p_firmware
- r7900p
- r8000_firmware
- r6400
- r7100lg_firmware
- r8000p_firmware
- r7100lg
- r6250
- r6400_firmware
- r7900p_firmware
- r6700
- r8000p
- r6400v2_firmware
- r7000_firmware
- r6300
- r8000
- rax80_firmware
- r6900
- r6900p
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')