CVE-2021-41383

CWE-77Command Injection3 documents3 sources
Severity
7.2HIGH
EPSS
1.2%
top 21.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 17
Latest updateMay 24

Description

setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-9q47-75mf-qmf9: setup2022-05-24
CVEList
CVE-2021-41383: setup2021-09-17
CVE-2021-41383 (HIGH CVSS 7.2) | setup.cgi on NETGEAR R6020 1.0.0.48 | cvebase.io