References https://nvd.nist.gov/vuln/detail/cve-2021-20166 https://github.com/advisories/GHSA-756v-gg77-ccw5 https://avd.aquasec.com/nvd/2021/cve-2021-20166/ https://access.redhat.com/security/cve/cve-2021-20166 https://vulners.com/nuclei/NUCLEI:CVE-2021-20167 https://www.nsfocus.net/vulndb/62613 https://cve.imfht.com/?vendor=Netgear&page=9 https://strobes.co/vi/cve/CVE-2021-20166/ https://cvedb.shodan.io/dashboard/vulnerabilities?version_id=1902224_4 https://vulmon.com/searchpage?q=netgear+rax43
Related VulnerabilitiesNetgear DGN2200 路由器 /RST_status.htm 权限绕过漏洞(CVE-2024-57046)PoCCVE-2016-1555: NETGEAR WNAP320 Access Point Firmware - Remote Command InjectionPoCCVE-2016-5649: NETGEAR DGN2200 / DGND3700 - Admin Password DisclosurePoCCVE-2016-6277: NETGEAR Routers - Remote Code ExecutionPoCCVE-2017-5521: NETGEAR Routers - Authentication BypassPoCCVE-2020-26919: NETGEAR ProSAFE Plus - Unauthenticated Remote Code ExecutionPoCCVE-2020-27866: NETGEAR - Authentication BypassPoCCVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer OverrunPoCCVE-2022-29383: NETGEAR ProSafe SSL VPN firmware - SQL InjectionPoCCVE-2024-30568: Netgear R6850 V1.1.0.88 - Command InjectionPoCCVE-2024-30569: Netgear R6850 - Information DisclosurePoCCVE-2024-30570: Netgear R6850 - Information DisclosurePoCCVE-2024-57046: Netgear DGN2200 - Improper Authentication