CVE-2021-45554

HIGH

NETGEAR R6400/R6400v2/R6700v3/R7000/R6900P/R7000P/R8000 Firmware - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.74, R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, R7000 before 1.0.11.126, R6900P before 1.3.3.140, R7000P before 1.3.3.140, and R8000 before 1.0.4.74.

Scores

CVSS v3 8.4
EPSS 0.0014
EPSS Percentile 33.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (7)
netgear/r6400_firmware < 1.0.1.74
netgear/r6400v2_firmware < 1.0.4.118
netgear/r6700v3_firmware < 1.0.4.118
netgear/r6900p_firmware < 1.3.3.140
netgear/r7000_firmware < 1.0.11.126
netgear/r7000p_firmware < 1.3.3.140
netgear/r8000_firmware < 1.0.4.74
Published Dec 26, 2021
Tracked Since Feb 18, 2026