CVE-2021-38530
CRITICALNETGEAR RBK/RBR/RBS Firmware - Unauthenticated Command Injection
Title source: llmDescription
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://kb.netgear.com/000063770/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-WiFi-Systems-PSV-2019-0151
Scores
CVSS v3
9.6
EPSS
0.0166
EPSS Percentile
82.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (10)
netgear/rbk20_firmware
< 2.5.1.16
netgear/rbk40_firmware
< 2.5.1.16
netgear/rbk50_firmware
< 2.5.1.16
netgear/rbr20_firmware
< 2.5.1.16
netgear/rbr40_firmware
< 2.5.1.16
netgear/rbr50_firmware
< 2.5.1.16
netgear/rbs20_firmware
< 2.5.1.16
netgear/rbs40_firmware
< 2.5.1.16
netgear/rbs50_firmware
< 2.5.1.16
netgear/rbs50y_firmware
< 2.6.1.40
Published
Aug 11, 2021
Tracked Since
Feb 18, 2026