CVE-2021-45619

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.134, EX7700 before 1.0.0.216, EX8000 before 1.0.1.232, LBR1020 before 2.6.3.58, LBR20 before 2.6.3.50, R7800 before 1.0.2.80, R8900 before 1.0.5.26, R9000 before 1.0.5.26, RBS50Y before 2.7.3.22, WNR2000v5 before 1.0.0.76, XR700 before 1.0.1.36, EX6150v2 before 1.0.1.98, EX7300 before 1.0.2.158, EX7320 before 1.0.0.134, RAX10 before 1.0.2.88, RAX120 before 1.2.0.16, RAX70 before 1.0.2.88, EX6100v2 before 1.0.1.98, EX6400 before 1.0.2.158, EX7300v2 before 1.0.0.134, R6700AX before 1.0.2.88, RAX120v2 before 1.2.0.16, RAX78 before 1.0.2.88, EX6410 before 1.0.0.134, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR350 before 4.3.4.7, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, EX6420 before 1.0.0.134, RBS10 before 2.7.3.22, RBS20 before 2.7.3.22, RBS350 before 4.3.4.7, RBS40 before 2.7.3.22, RBS50 before 2.7.3.22, EX6400v2 before 1.0.0.134, RBK12 before 2.7.3.22, RBK20 before 2.7.3.22, RBK352 before 4.3.4.7, RBK40 before 2.7.3.22, and RBK50 before 2.7.3.22.

Published: 2021-12-25 Last update: 2026-06-17 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-45619 is rated High Risk (68.7/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.49%). Core evidence: EPSS rose +1.47% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-45619

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 1.02% 2.49% +1.47%
2 2026-01-06 0.86% 1.02% +0.16%
3 2025-11-21 0.86%

Full EPSS history (14 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-45619

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.6 3.1 CRITICAL
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Click to expand
Attack vector (AV:A)
Attacker has to be nearby on the network—same office, same link, that vibe—not the whole wide internet.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.8 6.0 [email protected]
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2021-45619

Affected software / configurations for CVE-2021-45619

Vendor Product Version Raw CPE
netgear ex6250_firmware < 1.0.0.134 cpe:2.3:o:netgear:ex6250_firmware:*:*:*:*:*:*:*:*
netgear ex7700_firmware < 1.0.0.216 cpe:2.3:o:netgear:ex7700_firmware:*:*:*:*:*:*:*:*
netgear ex8000_firmware < 1.0.1.232 cpe:2.3:o:netgear:ex8000_firmware:*:*:*:*:*:*:*:*
netgear lbr1020_firmware < 2.6.3.58 cpe:2.3:o:netgear:lbr1020_firmware:*:*:*:*:*:*:*:*
netgear lbr20_firmware < 2.6.3.50 cpe:2.3:o:netgear:lbr20_firmware:*:*:*:*:*:*:*:*
netgear r7800_firmware < 1.0.2.80 cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:*
netgear r8900_firmware < 1.0.5.26 cpe:2.3:o:netgear:r8900_firmware:*:*:*:*:*:*:*:*
netgear rbs50y_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbs50y_firmware:*:*:*:*:*:*:*:*
netgear wnr2000v5_firmware < 1.0.0.76 cpe:2.3:o:netgear:wnr2000v5_firmware:*:*:*:*:*:*:*:*
netgear xr700_firmware < 1.0.1.36 cpe:2.3:o:netgear:xr700_firmware:*:*:*:*:*:*:*:*
netgear ex6150v2_firmware < 1.0.1.98 cpe:2.3:o:netgear:ex6150v2_firmware:*:*:*:*:*:*:*:*
netgear ex7300_firmware < 1.0.2.158 cpe:2.3:o:netgear:ex7300_firmware:*:*:*:*:*:*:*:*
netgear ex7320_firmware < 1.0.0.134 cpe:2.3:o:netgear:ex7320_firmware:*:*:*:*:*:*:*:*
netgear rax10_firmware < 1.0.2.88 cpe:2.3:o:netgear:rax10_firmware:*:*:*:*:*:*:*:*
netgear rax120_firmware < 1.2.0.16 cpe:2.3:o:netgear:rax120_firmware:*:*:*:*:*:*:*:*
netgear rax70_firmware < 1.0.2.88 cpe:2.3:o:netgear:rax70_firmware:*:*:*:*:*:*:*:*
netgear ex6100v2_firmware < 1.0.1.98 cpe:2.3:o:netgear:ex6100v2_firmware:*:*:*:*:*:*:*:*
netgear ex6400_firmware < 1.0.2.158 cpe:2.3:o:netgear:ex6400_firmware:*:*:*:*:*:*:*:*
netgear ex7300v2_firmware < 1.0.0.134 cpe:2.3:o:netgear:ex7300v2_firmware:*:*:*:*:*:*:*:*
netgear r6700ax_firmware < 1.0.2.88 cpe:2.3:o:netgear:r6700ax_firmware:*:*:*:*:*:*:*:*
netgear rax120v2_firmware < 1.2.0.16 cpe:2.3:o:netgear:rax120v2_firmware:*:*:*:*:*:*:*:*
netgear rax78_firmware < 1.0.2.88 cpe:2.3:o:netgear:rax78_firmware:*:*:*:*:*:*:*:*
netgear ex6410_firmware < 1.0.0.134 cpe:2.3:o:netgear:ex6410_firmware:*:*:*:*:*:*:*:*
netgear rbr10_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbr10_firmware:*:*:*:*:*:*:*:*
netgear rbr20_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbr20_firmware:*:*:*:*:*:*:*:*
netgear rbr350_firmware < 4.3.4.7 cpe:2.3:o:netgear:rbr350_firmware:*:*:*:*:*:*:*:*
netgear rbr40_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbr40_firmware:*:*:*:*:*:*:*:*
netgear rbr50_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbr50_firmware:*:*:*:*:*:*:*:*
netgear ex6420_firmware < 1.0.0.134 cpe:2.3:o:netgear:ex6420_firmware:*:*:*:*:*:*:*:*
netgear rbs10_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbs10_firmware:*:*:*:*:*:*:*:*
netgear rbs20_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbs20_firmware:*:*:*:*:*:*:*:*
netgear rbs350_firmware < 4.3.4.7 cpe:2.3:o:netgear:rbs350_firmware:*:*:*:*:*:*:*:*
netgear rbs40_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbs40_firmware:*:*:*:*:*:*:*:*
netgear rbs50_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbs50_firmware:*:*:*:*:*:*:*:*
netgear ex6400v2_firmware < 1.0.0.134 cpe:2.3:o:netgear:ex6400v2_firmware:*:*:*:*:*:*:*:*
netgear rbk12_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbk12_firmware:*:*:*:*:*:*:*:*
netgear rbk20_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbk20_firmware:*:*:*:*:*:*:*:*
netgear rbk352_firmware < 4.3.4.7 cpe:2.3:o:netgear:rbk352_firmware:*:*:*:*:*:*:*:*
netgear rbk40_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbk40_firmware:*:*:*:*:*:*:*:*
netgear rbk50_firmware < 2.7.3.22 cpe:2.3:o:netgear:rbk50_firmware:*:*:*:*:*:*:*:*
netgear ex6200v2_firmware < 1.0.1.86 cpe:2.3:o:netgear:ex6200v2_firmware:*:*:*:*:*:*:*:*
netgear r9000_firmware < 1.0.5.26 cpe:2.3:o:netgear:r9000_firmware:*:*:*:*:*:*:*:*

References for CVE-2021-45619

cvelogic Threat Intelligence