← Vulnerability feed

Vulnerability record · CVE-2021-20167 · published 30 December 2021

CVE-2021-20167: Netgear rax43 firmware command injection vulnerability

Netgear · Rax43 Firmware

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.

8.0 CVSS 3.1 High EPSS 7.8% · top 5.5% CWE-77 · Command injection
8.0CVSS 3.1 base score, v2 7.7
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45612Netgear cbr40 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …EPSS 2.5%9.8CVE-2021-45613Netgear cbr40 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …EPSS 2.0%9.8CVE-2021-45614Netgear d7000v2 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28…EPSS 2.0%9.8CVE-2021-45616Netgear cbr750 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28,…EPSS 2.0%9.8CVE-2021-45620Netgear cbr40 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …EPSS 2.0%9.8CVE-2021-45621Netgear cbr40 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2,…EPSS 2.0%9.8CVE-2021-45622Netgear cbr40 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, …EPSS 2.4%8.8CVE-2021-34982Netgear dc112a firmware stack-based buffer overflow vulnerabilityNETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2021-20167), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.