CVE-2021-29071
Summary
| CVE | CVE-2021-29071 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-23 07:15:00 UTC |
| Updated | 2021-03-24 19:40:00 UTC |
| Description | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBR752 before 3.2.17.12, RBR753 before 3.2.17.12, RBR753S before 3.2.17.12, RBR754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Rbk852 | - | All | All | All |
| Operating System | Netgear | Rbk852 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk853 | - | All | All | All |
| Operating System | Netgear | Rbk853 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk854 | - | All | All | All |
| Operating System | Netgear | Rbk854 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr750 | - | All | All | All |
| Operating System | Netgear | Rbr750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr752 | - | All | All | All |
| Operating System | Netgear | Rbr752 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr753 | - | All | All | All |
| Hardware | Netgear | Rbr753s | - | All | All | All |
| Operating System | Netgear | Rbr753s Firmware | All | All | All | All |
| Operating System | Netgear | Rbr753 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr754 | - | All | All | All |
| Operating System | Netgear | Rbr754 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr850 | - | All | All | All |
| Operating System | Netgear | Rbr850 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs750 | - | All | All | All |
| Operating System | Netgear | Rbs750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs850 | - | All | All | All |
| Operating System | Netgear | Rbs850 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Post-Authentication Command Injection on Some WiFi Systems, PSV-2020-0476 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.