CVE-2021-45601
Description
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated command injection in multiple NETGEAR WiFi system models allows attackers to execute arbitrary commands.
Vulnerability
A post-authentication command injection vulnerability exists in the firmware of several NETGEAR WiFi system models. The flaw affects CBR40 before version 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12 [1]. An authenticated user can inject arbitrary operating system commands through a vulnerable input field or API endpoint.
Exploitation
To exploit this vulnerability, an attacker must have valid credentials for the device's administrative interface and be on the same adjacent network (CVSS vector AV:A/PR:H) [1]. No user interaction is required beyond the attacker's own actions. The attacker can send crafted requests containing command injection payloads to the affected component, leading to execution of arbitrary commands with root privileges.
Impact
Successful exploitation grants the attacker full command execution on the device. This results in a complete compromise of confidentiality, integrity, and availability, with a scope change (CVSS 8.4, High) [1]. The attacker can read sensitive data, modify device configuration, install malware, or disrupt network services.
Mitigation
NETGEAR released fixed firmware versions on 2021-09-26: CBR40 2.5.0.24, CBR750 4.6.3.6, RBK852 3.2.17.12, RBR850 3.2.17.12, and RBS850 3.2.17.12 [1]. Users should update to the latest firmware immediately via the NETGEAR Support page. No workarounds are documented; the only mitigation is applying the patch.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/NETGEAR devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.