CVE-2021-29071

EUVD-2021-15712
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBR752 before 3.2.17.12, RBR753 before 3.2.17.12, RBR753S before 3.2.17.12, RBR754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
mitreCNA
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
netgearrbk852_firmware
𝑥
< 3.2.17.12
netgearrbk853_firmware
𝑥
< 3.2.17.12
netgearrbk854_firmware
𝑥
< 3.2.17.12
netgearrbr850_firmware
𝑥
< 3.2.17.12
netgearrbs850_firmware
𝑥
< 3.2.17.12
netgearrbr752_firmware
𝑥
< 3.2.17.12
netgearrbr753_firmware
𝑥
< 3.2.17.12
netgearrbr753s_firmware
𝑥
< 3.2.17.12
netgearrbr754_firmware
𝑥
< 3.2.17.12
netgearrbr750_firmware
𝑥
< 3.2.17.12
netgearrbs750_firmware
𝑥
< 3.2.17.12
𝑥
= Vulnerable software versions