CVE-2021-38527 describes a critical command injection vulnerability impacting numerous NETGEAR devices, including various Orbi and Nighthawk models. An unauthenticated attacker can exploit this flaw to execute arbitrary commands on affected devices. With a CVSS score of 9.8, this vulnerability poses a severe risk, allowing for complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion, indicating potential future interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.0.14CPE matchmatch criteria | cpe:2.3:o:netgear:cbr40_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.98CPE matchmatch criteria | cpe:2.3:o:netgear:ex6100_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.98CPE matchmatch criteria | cpe:2.3:o:netgear:ex6150_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.132CPE matchmatch criteria | cpe:2.3:o:netgear:ex6250_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.2.158CPE matchmatch criteria | cpe:2.3:o:netgear:ex6400_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.