CVE-2021-45556

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.36, GS110TPP before 7.0.7.2, GS110TPv2 before 5.4.2.36., GS110TPv3 before 7.0.7.2, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:H
mitreCNA
7.5 HIGH
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AC:H/AV:A/A:H/C:L/I:H/PR:H/S:C/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
netgeargs108tv2_firmware
𝑥
< 5.4.2.36
netgeargs110tpp_firmware
𝑥
< 7.0.7.2
netgeargs110tpv2_firmware
𝑥
< 5.4.2.36
netgeargs308t_firmware
𝑥
< 1.0.3.2
netgeargs110tpv3_firmware
𝑥
< 7.0.7.2
netgeargs310tp_firmware
𝑥
< 1.0.3.2
netgeargs724tpp_firmware
𝑥
< 2.0.6.3
netgeargs724tpv2_firmware
𝑥
< 2.0.6.3
netgeargs728tppv2_firmware
𝑥
< 6.0.8.2
netgeargs728tpv2_firmware
𝑥
< 6.0.8.2
netgeargs752tpp_firmware
𝑥
< 6.0.8.2
netgeargs752tpv2_firmware
𝑥
< 6.0.8.2
netgearms510txm_firmware
𝑥
< 1.0.4.2
netgearms510txup_firmware
𝑥
< 1.0.4.2
𝑥
= Vulnerable software versions