CVE-2021-33514

CRITICALCVSS 9.8/10EPSS 8.80%

Last modified

CVE-2021-33514 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field. This affects GC108P before 1.0.7.3, GC108PP before 1.0.7.3, GS108Tv3 before 7.0.6.3, GS110TPPv1 before 7.0.6.3, GS110TPv3 before 7.0.6.3, GS110TUPv1 before 1.0.4.3, GS710TUPv1 before 1.0.4.3, GS716TP before 1.0.2.3, GS716TPP before 1.0.2.3, GS724TPPv1 before 2.0.4.3, GS724TPv2 before 2.0.4.3, GS728TPPv2 before 6.0.6.3, GS728TPv2 before 6.0.6.3, GS752TPPv1 before 6.0.6.3, GS752TPv2 before 6.0.6.3, MS510TXM before 1.0.2.3, and MS510TXUP before 1.0.2.3.. EPSS estimates a 8.80% chance of exploitation in the next 30 days.

Description

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field. This affects GC108P before 1.0.7.3, GC108PP before 1.0.7.3, GS108Tv3 before 7.0.6.3, GS110TPPv1 before 7.0.6.3, GS110TPv3 before 7.0.6.3, GS110TUPv1 before 1.0.4.3, GS710TUPv1 before 1.0.4.3, GS716TP before 1.0.2.3, GS716TPP before 1.0.2.3, GS724TPPv1 before 2.0.4.3, GS724TPv2 before 2.0.4.3, GS728TPPv2 before 6.0.6.3, GS728TPv2 before 6.0.6.3, GS752TPPv1 before 6.0.6.3, GS752TPv2 before 6.0.6.3, MS510TXM before 1.0.2.3, and MS510TXUP before 1.0.2.3.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
8.80%

94.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearGc108p Firmware< 1.0.7.3
NetgearGc108pp Firmware< 1.0.7.3
NetgearGs108t Firmware< 7.0.6.3
NetgearGs110tpp Firmware< 7.0.6.3
NetgearGs110tp Firmware< 7.0.6.3
NetgearGs110tup Firmware< 1.0.4.3
NetgearGs710tup Firmware< 1.0.4.3
NetgearGs716tp Firmware< 1.0.2.3
NetgearGs716tpp Firmware< 1.0.2.3
NetgearGs724tpp Firmware< 2.0.4.3
NetgearGs724tp Firmware< 2.0.4.3
NetgearGs728tpp Firmware< 6.0.6.3
NetgearGs728tp Firmware< 6.0.6.3
NetgearGs752tpp Firmware< 6.0.6.3
NetgearGs752tp Firmware< 6.0.6.3
NetgearMs510txm Firmware< 1.0.2.3
NetgearMs510txup Firmware< 1.0.2.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-33514?
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field. This affects GC108P before 1.0.7.3, GC108PP before 1.0.7.3, GS108Tv3 before 7.0.6.3, GS110TPPv1 before 7.0.6.3, GS110TPv3 before 7.0.6.3, GS110TUPv1 before 1.0.4.3, GS710TUPv1 before 1.0.4.3, GS716TP before 1.0.2.3, GS716TPP before 1.0.2.3, GS724TPPv1 before 2.0.4.3, GS724TPv2 before 2.0.4.3, GS728TPPv2 before 6.0.6.3, GS728TPv2 before 6.0.6.3, GS752TPPv1 before 6.0.6.3, GS752TPv2 before 6.0.6.3, MS510TXM before 1.0.2.3, and MS510TXUP before 1.0.2.3.
How severe is CVE-2021-33514?
CVE-2021-33514 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 8.80% probability of exploitation in the next 30 days.
How do I fix CVE-2021-33514?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-33514?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST