CVE-2021-45595
Summary
| CVE | CVE-2021-45595 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-26 01:15:00 UTC |
| Updated | 2022-01-05 20:38:00 UTC |
| Description | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, RBS10 before 2.7.3.22, RBS20 before 2.7.3.22, RBS40 before 2.7.3.22, RBS50 before 2.7.3.22, RBK12 before 2.7.3.22, RBK20 before 2.7.3.22, RBK40 before 2.7.3.22, and RBK50 before 2.7.3.22. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Lbr20 | - | All | All | All |
| Operating System | Netgear | Lbr20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk12 | - | All | All | All |
| Operating System | Netgear | Rbk12 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk20 | - | All | All | All |
| Operating System | Netgear | Rbk20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk40 | - | All | All | All |
| Operating System | Netgear | Rbk40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk50 | - | All | All | All |
| Operating System | Netgear | Rbk50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr10 | - | All | All | All |
| Operating System | Netgear | Rbr10 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr20 | - | All | All | All |
| Operating System | Netgear | Rbr20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr40 | - | All | All | All |
| Operating System | Netgear | Rbr40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr50 | - | All | All | All |
| Operating System | Netgear | Rbr50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs10 | - | All | All | All |
| Operating System | Netgear | Rbs10 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs20 | - | All | All | All |
| Operating System | Netgear | Rbs20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs40 | - | All | All | All |
| Operating System | Netgear | Rbs40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs50 | - | All | All | All |
| Hardware | Netgear | Rbs50y | - | All | All | All |
| Operating System | Netgear | Rbs50y Firmware | All | All | All | All |
| Operating System | Netgear | Rbs50 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Post-Authentication Command Injection on Some WiFi Systems, PSV-2020-0462 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.