CVE-2021-45602
moderate-risk
Published 2021-12-26
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46.
Do I need to act?
-
0.10% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10
Medium
LOCAL
/ LOW complexity
Affected Products (18)
Wn3000Rpv2 Firmware
Wn3000Rpv3 Firmware
Lbr1020 Firmware
Lbr20 Firmware
R6700Ax Firmware
Rax10 Firmware
Rax120V1 Firmware
Rax120V2 Firmware
Rax70 Firmware
Rax78 Firmware
Affected Vendors
References (4)
Third Party Advisory
https://immersivelabs.com/resources/blog/netgear-vulnerabilities-could-put-small...
Third Party Advisory
https://immersivelabs.com/resources/blog/netgear-vulnerabilities-could-put-small...
39
/ 100
moderate-risk
Severity
20/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
19/34 · Moderate