CVE-2021-45602
Summary
| CVE | CVE-2021-45602 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-26 01:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | D7800 | - | All | All | All |
| Operating System | Netgear | D7800 Firmware | All | All | All | All |
| Hardware | Netgear | Ex2700 | - | All | All | All |
| Operating System | Netgear | Ex2700 Firmware | All | All | All | All |
| Hardware | Netgear | Lbr1020 | - | All | All | All |
| Operating System | Netgear | Lbr1020 Firmware | All | All | All | All |
| Hardware | Netgear | Lbr20 | - | All | All | All |
| Operating System | Netgear | Lbr20 Firmware | All | All | All | All |
| Hardware | Netgear | R6700ax | - | All | All | All |
| Operating System | Netgear | R6700ax Firmware | All | All | All | All |
| Hardware | Netgear | R7800 | - | All | All | All |
| Operating System | Netgear | R7800 Firmware | All | All | All | All |
| Hardware | Netgear | R8900 | - | All | All | All |
| Operating System | Netgear | R8900 Firmware | All | All | All | All |
| Hardware | Netgear | R9000 | - | All | All | All |
| Operating System | Netgear | R9000 Firmware | All | All | All | All |
| Hardware | Netgear | Rax10 | - | All | All | All |
| Operating System | Netgear | Rax10 Firmware | All | All | All | All |
| Hardware | Netgear | Rax120v1 | - | All | All | All |
| Operating System | Netgear | Rax120v1 Firmware | All | All | All | All |
| Hardware | Netgear | Rax120v2 | - | All | All | All |
| Operating System | Netgear | Rax120v2 Firmware | All | All | All | All |
| Hardware | Netgear | Rax70 | - | All | All | All |
| Operating System | Netgear | Rax70 Firmware | All | All | All | All |
| Hardware | Netgear | Rax78 | - | All | All | All |
| Operating System | Netgear | Rax78 Firmware | All | All | All | All |
| Hardware | Netgear | Wn3000rpv2 | - | All | All | All |
| Operating System | Netgear | Wn3000rpv2 Firmware | All | All | All | All |
| Hardware | Netgear | Wn3000rpv3 | - | All | All | All |
| Operating System | Netgear | Wn3000rpv3 Firmware | All | All | All | All |
| Hardware | Netgear | Xr450 | - | All | All | All |
| Operating System | Netgear | Xr450 Firmware | All | All | All | All |
| Hardware | Netgear | Xr500 | - | All | All | All |
| Operating System | Netgear | Xr500 Firmware | All | All | All | All |
| Hardware | Netgear | Xr700 | - | All | All | All |
| Operating System | Netgear | Xr700 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Post-Authentication Command Injection & Sensitive Information Disclosure on Multiple Products, PSV-2021-0169 & PSV-2021-0171 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| Netgear vulnerabilities could put small business routers at risk - Immersive Labs | MISC | immersivelabs.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.