cbcvebase.
CVE-2021-38528
published 2021-08-11

CVE-2021-38528: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 before 1.0.3.56.

Affected

6 ranges
VendorProductVersion rangeFixed in
netgeard8500_firmware< 1.0.3.581.0.3.58
netgearr6900p_firmware< 1.3.2.1321.3.2.132
netgearr7000p_firmware< 1.3.2.1321.3.2.132
netgearr7100lg_firmware< 1.0.0.641.0.0.64
netgearwndr3400_firmware< 1.0.1.381.0.1.38
netgearxr300_firmware< 1.0.3.561.0.3.56