Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
18 Aug 2021, 20:23
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 7.2 |
CPE | cpe:2.3:h:netgear:r6400:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700:v2:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r6900:v2:*:*:*:*:*:*:* |
|
CWE | CWE-77 | |
References | (MISC) https://kb.netgear.com/000063763/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2018-0565 - Vendor Advisory |
11 Aug 2021, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-11 00:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-38520
Mitre link : CVE-2021-38520
CVE.ORG link : CVE-2021-38520
JSON object : View
Products Affected
netgear
- r6700_firmware
- r7000p
- r6400_firmware
- r6900_firmware
- r6400
- r6900
- r6700
- r7000p_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')