CVE-2021-45595

Published: Dic 26, 2021 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2021-32361 Aliases: GSD-2021-45595
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,6
Attack Vector: adjacent_network
Attack Complexity: high
Privileges Required: high
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
MEDIUM 6,5
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, RBS10 before 2.7.3.22, RBS20 before 2.7.3.22, RBS40 before 2.7.3.22, RBS50 before 2.7.3.22, RBK12 before 2.7.3.22, RBK20 before 2.7.3.22, RBK40 before 2.7.3.22, and RBK50 before 2.7.3.22.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0024
Percentile
0,5th
Updated

EPSS Score Trend (Last 90 Days)

77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: AI/ML
View CWE Details
Operating System

Rbr40 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbr40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Lbr20 Firmware by Netgear

Version Range Affected
To 2.6.3.50 (exclusive)
cpe:2.3:o:netgear:lbr20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs20 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbs20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs40 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbs40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk50 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbk50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr20 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbr20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs50 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbs50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs50Y Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbs50y_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs10 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbs10_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk20 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbk20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr50 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbr50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk40 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbk40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr10 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbr10_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk12 Firmware by Netgear

Version Range Affected
To 2.7.3.22 (exclusive)
cpe:2.3:o:netgear:rbk12_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://kb.netgear.com/000064495/Security-Advisory-for-Post-Authentication-Comm…
https://kb.netgear.com/000064495/Security-Advisory-for-Post-Authentication-Comm…