CVE-2021-45625
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects XR300 before 1.0.3.68, R7000P before 1.3.3.140, and R6900P before 1.3.3.140.
Affected (3)
Products: Netgear: Xr300 Firmware, R7000p Firmware, R6900p Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.3.68 |
| Running on/with | Platform Versions |
|---|---|
Netgear Xr300 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3.3.140 |
| Running on/with | Platform Versions |
|---|---|
Netgear R7000p | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.3.3.140 |
| Running on/with | Platform Versions |
|---|---|
Netgear R6900p | All versions |
References (2)
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.