CVE-2021-45556

HIGHCVSS 8.8/10EPSS 1.22%

Last modified

CVE-2021-45556 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.36, GS110TPP before 7.0.7.2, GS110TPv2 before 5.4.2.36., GS110TPv3 before 7.0.7.2, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.. EPSS estimates a 1.22% chance of exploitation in the next 30 days.

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.36, GS110TPP before 7.0.7.2, GS110TPv2 before 5.4.2.36., GS110TPv3 before 7.0.7.2, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.22%

64.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearGs108tv2 Firmware< 5.4.2.36
NetgearGs110tpp Firmware< 7.0.7.2
NetgearGs110tpv2 Firmware< 5.4.2.36
NetgearGs308t Firmware< 1.0.3.2
NetgearGs110tpv3 Firmware< 7.0.7.2
NetgearGs310tp Firmware< 1.0.3.2
NetgearGs724tpp Firmware< 2.0.6.3
NetgearGs724tpv2 Firmware< 2.0.6.3
NetgearGs728tppv2 Firmware< 6.0.8.2
NetgearGs728tpv2 Firmware< 6.0.8.2
NetgearGs752tpp Firmware< 6.0.8.2
NetgearGs752tpv2 Firmware< 6.0.8.2
NetgearMs510txm Firmware< 1.0.4.2
NetgearMs510txup Firmware< 1.0.4.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-45556?
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.36, GS110TPP before 7.0.7.2, GS110TPv2 before 5.4.2.36., GS110TPv3 before 7.0.7.2, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.
How severe is CVE-2021-45556?
CVE-2021-45556 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.22% probability of exploitation in the next 30 days.
How do I fix CVE-2021-45556?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-45556?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST