Command Injection in NETGEAR products - #VU73743
Published: March 16, 2023
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation. A remote administrator can pass specially crafted data to the application and execute arbitrary commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
RAX48
RAX50S
RAX50
RAX45
RAX43
RAX42
RAX40v2
RAX38v2
RAX35v2
RAX200
RAX80
RAX75
RAXE500
RAXE450
RAX15
RAX20
MR80
MK83
MS80
LAX20
MK62
MS60
MR60
R7960P
R8000P
NBR750
RBK752
RBR750
RBS750
RBK840
RBR840
RBS840
RBK852
RBR850
RBS850
CBR750
RBKE962
RBRE960
RBSE960
Remediation
RAX48 - update to 1.0.4.100
RAX50S - update to 1.0.4.100
RAX50 - update to 1.0.4.100
RAX45 - update to 1.0.4.100
RAX43 - update to 1.0.4.100
RAX42 - update to 1.0.4.100
RAX40v2 - update to 1.0.4.100
RAX38v2 - update to 1.0.4.100
RAX35v2 - update to 1.0.4.100
RAX200 - update to 1.0.6.138
RAX80 - update to 1.0.6.138
RAX75 - update to 1.0.6.138
RAXE500 - update to 1.0.8.70
RAXE450 - update to 1.0.8.70
RAX15 - update to 1.0.10.110
RAX20 - update to 1.0.10.110
MR80 - update to 1.1.6.14
MK83 - update to 1.1.6.14
MS80 - update to 1.1.6.14
LAX20 - update to 1.1.6.30
MK62 - update to 1.1.6.122
MS60 - update to 1.1.6.122
MR60 - update to 1.1.6.122
R7960P - update to 1.4.4.94
R8000P - update to 1.4.4.94
NBR750 - update to 4.6.5.11
RBK752 - update to 4.6.7.13
RBR750 - update to 4.6.7.13
RBS750 - update to 4.6.7.13
RBK840 - update to 4.6.7.13
RBR840 - update to 4.6.7.13
RBS840 - update to 4.6.7.13
RBK852 - update to 4.6.7.13
RBR850 - update to 4.6.7.13
RBS850 - update to 4.6.7.13
CBR750 - update to 4.6.14.4
RBKE962 - update to 6.0.3.68
RBRE960 - update to 6.0.3.68
RBSE960 - update to 6.0.3.68