ID

VAR-202112-2322


CVE

CVE-2021-45627


TITLE

Netgear NETGEAR Command injection vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202112-2421

DESCRIPTION

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12. This affects CBR750 prior to 4.6.3.6, RBK852 prior to 3.2.17.12, RBR850 prior to 3.2.17.12, and RBS850 prior to 3.2.17.12

Trust: 0.99

sources: NVD: CVE-2021-45627 // VULMON: CVE-2021-45627

AFFECTED PRODUCTS

vendor:netgearmodel:rbk852scope:ltversion:3.2.17.12

Trust: 1.0

vendor:netgearmodel:rbr850scope:ltversion:3.2.17.12

Trust: 1.0

vendor:netgearmodel:rbs850scope:ltversion:3.2.17.12

Trust: 1.0

vendor:netgearmodel:cbr750scope:ltversion:4.6.3.6

Trust: 1.0

sources: NVD: CVE-2021-45627

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2021-45627
value: CRITICAL

Trust: 1.0

CNNVD: CNNVD-202112-2421
value: CRITICAL

Trust: 0.6

VULMON: CVE-2021-45627
value: HIGH

Trust: 0.1

VULMON: CVE-2021-45627
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: CVE-2021-45627
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: VULMON: CVE-2021-45627 // CNNVD: CNNVD-202112-2421 // NVD: CVE-2021-45627

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.0

sources: NVD: CVE-2021-45627

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-2421

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-202112-2421

CONFIGURATIONS

sources: NVD: CVE-2021-45627

PATCH

title:Netgear NETGEAR Fixes for command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=177129

Trust: 0.6

sources: CNNVD: CNNVD-202112-2421

EXTERNAL IDS

db:NVDid:CVE-2021-45627

Trust: 1.7

db:CNNVDid:CNNVD-202112-2421

Trust: 0.6

db:VULMONid:CVE-2021-45627

Trust: 0.1

sources: VULMON: CVE-2021-45627 // CNNVD: CNNVD-202112-2421 // NVD: CVE-2021-45627

REFERENCES

url:https://kb.netgear.com/000064124/security-advisory-for-pre-authentication-command-injection-on-some-wifi-systems-psv-2020-0471

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-45627

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/77.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2021-45627 // CNNVD: CNNVD-202112-2421 // NVD: CVE-2021-45627

SOURCES

db:VULMONid:CVE-2021-45627
db:CNNVDid:CNNVD-202112-2421
db:NVDid:CVE-2021-45627

LAST UPDATE DATE

2022-05-04T10:07:01.094000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-45627date:2022-01-04T00:00:00
db:CNNVDid:CNNVD-202112-2421date:2022-01-05T00:00:00
db:NVDid:CVE-2021-45627date:2022-01-04T20:54:00

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-45627date:2021-12-26T00:00:00
db:CNNVDid:CNNVD-202112-2421date:2021-12-26T00:00:00
db:NVDid:CVE-2021-45627date:2021-12-26T01:15:00