Vulnerability Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.2.74, R9000 before 1.0.5.2, and XR500 before 2.3.2.66.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | R7800 Firmware | < 1.0.2.74 |
| Netgear | R7800 | - |
| Netgear | R9000 Firmware | < 1.0.5.2 |
| Netgear | R9000 | - |
| Netgear | Xr500 Firmware | < 2.3.2.66 |
| Netgear | Xr500 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000064449/Security-Advisory-for-Pre-Authentication-CommanPatchVendor Advisory
- https://kb.netgear.com/000064449/Security-Advisory-for-Pre-Authentication-CommanPatchVendor Advisory
FAQ
What is CVE-2021-45623?
CVE-2021-45623 is a vulnerability with a CVSS score of 8.3 (HIGH). Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.2.74, R9000 before 1.0.5.2, and XR500 before 2.3.2.66.
How severe is CVE-2021-45623?
CVE-2021-45623 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45623?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear R7800 Firmware, Netgear R7800, Netgear R9000 Firmware, Netgear R9000, Netgear Xr500 Firmware.