Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.
                
            References
                    Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
Configuration 4 (hide)
| AND | 
 
 | 
Configuration 5 (hide)
| AND | 
 
 | 
Configuration 6 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 06:17
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://kb.netgear.com/000063763/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2018-0565 - Vendor Advisory | |
| CVSS | v2 : v3 : | v2 : 6.5 v3 : 6.6 | 
18 Aug 2021, 20:23
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://kb.netgear.com/000063763/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2018-0565 - Vendor Advisory | |
| CVSS | v2 : v3 : | v2 : 6.5 v3 : 7.2 | 
| CPE | cpe:2.3:h:netgear:r6400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700:v2:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6900:v2:*:*:*:*:*:*:* | |
| CWE | CWE-77 | 
11 Aug 2021, 00:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-08-11 00:15
Updated : 2024-11-21 06:17
NVD link : CVE-2021-38520
Mitre link : CVE-2021-38520
CVE.ORG link : CVE-2021-38520
JSON object : View
Products Affected
                netgear
- r6700_firmware
- r7000p
- r6900
- r6900_firmware
- r6700
- r6400
- r6400_firmware
- r7000p_firmware
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
