VYPR
Unrated severityNVD Advisory· Published Dec 26, 2021· Updated Aug 4, 2024

CVE-2021-45555

CVE-2021-45555

Description

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, and R8000P before 1.4.2.84.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated command injection in NETGEAR R7900P, R7960P, and R8000P routers allows attackers to execute arbitrary commands via the web interface.

Vulnerability

A post-authentication command injection vulnerability exists in the web interface of NETGEAR R7900P, R7960P, and R8000P routers running firmware versions prior to 1.4.2.84. An authenticated user can inject arbitrary operating system commands through a vulnerable parameter in the web management interface [1].

Exploitation

An attacker must first obtain valid credentials for the router's web interface. Once authenticated, the attacker can send specially crafted HTTP requests to the vulnerable endpoint, injecting commands that are executed by the underlying operating system. No user interaction beyond authentication is required [1].

Impact

Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the affected router. This can lead to full device compromise, including unauthorized access to network traffic, modification of router settings, and potential pivoting to other devices on the network [1].

Mitigation

NETGEAR has released firmware version 1.4.2.84 to address this vulnerability. Users are strongly advised to update their devices to the latest firmware. No workarounds are provided in the advisory [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.