Critical Remote Code Execution Vulnerability Found in Multiple Netgear Router Models
On September 22, 2021, networking company Netgear alerted users about a critical remote code execution (RCE) vulnerability, identified as CVE-2021-40847 (CVSS score: 8.1), affecting various router models. This weakness could allow remote attackers to gain control of affected systems. Netgear has released firmware updates to address the issue for the following models:
- R6400v2 (version 1.0.4.120)
- R6700 (version 1.0.2.26)
- R6700v3 (version 1.0.4.120)
- R6900 (version 1.0.2.26)
- R6900P (version 3.3.142_HOTFIX)
- R7000 (version 1.0.11.128)
- R7000P (version 1.3.3.142_HOTFIX)
- R7850 (version 1.0.5.76)
- R7900 (version 1.0.4.46)
- R8000 (version 1.0.4.76)
- RS400 (version 1.5.1.80)
Security researcher Adam Nichols from GRIMM noted that the vulnerability is linked to Circle, a third-party component integrated into the router firmware.
Critical Remote Code Execution Vulnerability Found in Multiple Netgear Router Models On September 22, 2021, networking equipment manufacturer Netgear announced the release of crucial patches to address a high-severity remote code execution vulnerability that could allow unauthorized attackers to gain control over affected routers. This vulnerability, assigned the identifier CVE-2021-40847…
Critical Remote Code Execution Vulnerability Found in Multiple Netgear Router Models
On September 22, 2021, networking company Netgear alerted users about a critical remote code execution (RCE) vulnerability, identified as CVE-2021-40847 (CVSS score: 8.1), affecting various router models. This weakness could allow remote attackers to gain control of affected systems. Netgear has released firmware updates to address the issue for the following models:
- R6400v2 (version 1.0.4.120)
- R6700 (version 1.0.2.26)
- R6700v3 (version 1.0.4.120)
- R6900 (version 1.0.2.26)
- R6900P (version 3.3.142_HOTFIX)
- R7000 (version 1.0.11.128)
- R7000P (version 1.3.3.142_HOTFIX)
- R7850 (version 1.0.5.76)
- R7900 (version 1.0.4.46)
- R8000 (version 1.0.4.76)
- RS400 (version 1.5.1.80)
Security researcher Adam Nichols from GRIMM noted that the vulnerability is linked to Circle, a third-party component integrated into the router firmware.