OS Command Injection in NETGEAR products - #VU70577

 

OS Command Injection in NETGEAR products - #VU70577

Published: January 2, 2023


Vulnerability identifier: #VU70577
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the device.

The vulnerability exists due to improper input validation. A remote authenticated user can send specially crafted data to the application and execute arbitrary OS commands on the device.



Affected software

XR1000
R7000P
RS400
RAX20
RAX15
RAX35v2
RAX40v2
RAX45
RAX50
RAX43
RAX200
RAX75
RAX80
MS60
MR60
MK62
MR80
MS80
MK83
LAX20
R7960P
R8000P
CBR40
RBS750
RBR750
RBK752
RBS850
RBR850
RBK852
CBR750

Remediation

Install updates from vendor's website.

XR1000 - update to 1.0.0.58
RAX20 - update to 1.0.3.96
RAX15 - update to 1.0.3.96
RAX35v2 - update to 1.0.3.96
RAX40v2 - update to 1.0.3.96
RAX45 - update to 1.0.3.96
RAX50 - update to 1.0.3.96
RAX43 - update to 1.0.3.96
RAX200 - update to 1.0.4.120
RAX75 - update to 1.0.4.120
RAX80 - update to 1.0.4.120
MS60 - update to 1.0.6.116
MR60 - update to 1.0.6.116
MK62 - update to 1.0.6.116
MR80 - update to 1.1.3.6
MS80 - update to 1.1.3.6
MK83 - update to 1.1.3.6
LAX20 - update to 1.1.6.28
R7000P - update to 1.3.3.140
R7960P - update to 1.4.2.84
R8000P - update to 1.4.2.84
RS400 - update to 1.5.1.80
CBR40 - update to 2.5.0.24
RBS750 - update to 3.2.17.12
RBR750 - update to 3.2.17.12
RBK752 - update to 3.2.17.12
RBS850 - update to 3.2.17.12
RBR850 - update to 3.2.17.12
RBK852 - update to 3.2.17.12
CBR750 - update to 4.6.3.6

External References

Related Security Bulletins