CVE-2021-45591
Description
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated command injection in multiple NETGEAR WiFi systems (RBK/RBR/RBS) prior to firmware 3.2.16.6 allows arbitrary command execution.
Vulnerability
The vulnerability is a post-authentication command injection affecting NETGEOr WiFi system models. Specifically, it impacts RBK752, RBR750, RBS750, RBK852, RBR850, and RBS850 before firmware version 3.2.16.6. An authenticated user can inject arbitrary commands into a vulnerable parameter, leading to execution on the device's underlying operating system [1].
Exploitation
To exploit this, an attacker must first obtain valid authentication credentials for the device's web interface or management API. Once authenticated, the attacker can send a crafted request containing malicious command injection payloads within a specific input field. No special network position is required beyond being able to reach the device's management interface over the network (adjacent network access is sufficient) [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands with root-level privileges on the affected device. This can lead to full compromise of the device, including data exfiltration, installation of persistent malware, further network attacks, and complete loss of confidentiality, integrity, and availability of the device's functions [1].
Mitigation
NETGEAR has released firmware version 3.2.16.6 (or later) to fix this vulnerability. Users should immediately update their devices to this version by downloading the firmware from the NETGEAR Support page and following the installation instructions. No workarounds are provided; NETGEAR strongly recommends the firmware upgrade as soon as possible [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7- NETGEAR/NETGEAR devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.