CVE-2021-45660

Severity
7.8HIGH
EPSS
0.1%
top 69.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 26
Latest updateDec 27

Description

Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages10 packages

NVDnetgear/rbs50y_firmware< 2.6.1.40
NVDnetgear/rbk20_firmware< 2.5.1.16
NVDnetgear/rbk40_firmware< 2.5.1.16
NVDnetgear/rbk50_firmware< 2.5.1.16
NVDnetgear/rbr20_firmware< 2.5.1.16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8wjc-jqj9-pv2v: Certain NETGEAR devices are affected by server-side injection2021-12-27
CVEList
CVE-2021-45660: Certain NETGEAR devices are affected by server-side injection2021-12-26
CVE-2021-45660 (HIGH CVSS 7.8) | Certain NETGEAR devices are affecte | cvebase.io