CVE-2021-38527
Summary
| CVE | CVE-2021-38527 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-11 00:16:00 UTC |
| Updated | 2021-08-19 18:37:00 UTC |
| Description | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0.2.158, EX6400v2 before 1.0.0.132, EX6410 before 1.0.0.132, EX6420 before 1.0.0.132, EX7300 before 1.0.2.158, EX7300v2 before 1.0.0.132, EX7320 before 1.0.0.132, EX7700 before 1.0.0.216, EX8000 before 1.0.1.232, R7800 before 1.0.2.78, RBK12 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, RBK20 before 2.6.1.38, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.38, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RBS40V before 2.6.2.4, RBS50Y before 2.6.1.40, RBW30 before 2.6.2.2, and XR500 before 2.3.2.114. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Cbr40 | - | All | All | All |
| Operating System | Netgear | Cbr40 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6100 | v2 | All | All | All |
| Operating System | Netgear | Ex6100 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6150 | v2 | All | All | All |
| Operating System | Netgear | Ex6150 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6250 | - | All | All | All |
| Operating System | Netgear | Ex6250 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6400 | - | All | All | All |
| Hardware | Netgear | Ex6400 | v2 | All | All | All |
| Operating System | Netgear | Ex6400 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6410 | - | All | All | All |
| Operating System | Netgear | Ex6410 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6420 | - | All | All | All |
| Operating System | Netgear | Ex6420 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7300 | - | All | All | All |
| Hardware | Netgear | Ex7300 | v2 | All | All | All |
| Operating System | Netgear | Ex7300 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7320 | - | All | All | All |
| Operating System | Netgear | Ex7320 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7700 | - | All | All | All |
| Operating System | Netgear | Ex7700 Firmware | All | All | All | All |
| Hardware | Netgear | Ex8000 | - | All | All | All |
| Operating System | Netgear | Ex8000 Firmware | All | All | All | All |
| Hardware | Netgear | R7800 | - | All | All | All |
| Operating System | Netgear | R7800 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk12 | - | All | All | All |
| Operating System | Netgear | Rbk12 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk20 | - | All | All | All |
| Operating System | Netgear | Rbk20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk40 | - | All | All | All |
| Operating System | Netgear | Rbk40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk50 | - | All | All | All |
| Operating System | Netgear | Rbk50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk752 | - | All | All | All |
| Operating System | Netgear | Rbk752 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk852 | - | All | All | All |
| Operating System | Netgear | Rbk852 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr10 | - | All | All | All |
| Operating System | Netgear | Rbr10 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr20 | - | All | All | All |
| Operating System | Netgear | Rbr20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr40 | - | All | All | All |
| Operating System | Netgear | Rbr40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr50 | - | All | All | All |
| Operating System | Netgear | Rbr50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr750 | - | All | All | All |
| Operating System | Netgear | Rbr750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr850 | - | All | All | All |
| Operating System | Netgear | Rbr850 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs10 | - | All | All | All |
| Operating System | Netgear | Rbs10 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs20 | - | All | All | All |
| Operating System | Netgear | Rbs20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs40 | - | All | All | All |
| Hardware | Netgear | Rbs40v | - | All | All | All |
| Operating System | Netgear | Rbs40v Firmware | All | All | All | All |
| Operating System | Netgear | Rbs40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs50 | - | All | All | All |
| Hardware | Netgear | Rbs50y | - | All | All | All |
| Operating System | Netgear | Rbs50y Firmware | All | All | All | All |
| Operating System | Netgear | Rbs50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs750 | - | All | All | All |
| Operating System | Netgear | Rbs750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs850 | - | All | All | All |
| Operating System | Netgear | Rbs850 Firmware | All | All | All | All |
| Hardware | Netgear | Rbw30 | - | All | All | All |
| Operating System | Netgear | Rbw30 Firmware | All | All | All | All |
| Hardware | Netgear | Xr500 | - | All | All | All |
| Operating System | Netgear | Xr500 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Pre-Authentication Command Injection on Some Extenders, Routers, and WiFi Systems, PSV-2020-0025 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.