S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-20167 Scanner

CVE-2021-20167 scanner - Command Injection vulnerability in Netgear RAX43

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-20167
8.0
CVSS

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Netgear RAX43by n/a
1.0.3.96
Updated Aug 21, 2026View on NVD →
Detail

Netgear RAX43 is a wireless router that is designed to provide users with high-speed internet connectivity and improved network coverage. The device is used to connect multiple devices to the internet simultaneously. The powerful router is equipped with advanced features that make it suitable for creating home and office networks. Netgear RAX43 is known for its superior performance, reliability, and security, however, the recent detection of a vulnerability has raised concerns among users.

CVE-2021-20167 is a critical vulnerability that was discovered in Netgear RAX43 version 1.0.3.96. The vulnerability exists in the readycloud cgi application, and it is caused by a command injection vulnerability in the name parameter. This vulnerability can be exploited by attackers to execute arbitrary code on the router remotely. Attackers can use various methods to exploit this vulnerability, such as sending specially crafted requests to the router or using a malicious script.

If this vulnerability is exploited, attackers can gain unauthorized access to the device and take control of it. This can result in a wide range of consequences, including the theft of sensitive information, data loss, and damage to the network infrastructure. Hackers can also use the compromised router as a launching pad to conduct further attacks on other devices on the same network.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides advanced tools and resources for detecting and addressing security issues in devices, applications, and networks. With the help of the s4e.io platform, users can stay protected against the latest security threats and vulnerabilities.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Install the latest firmware update from Netgear that includes a fix for this vulnerability.
  • Disable remote management of the router to prevent attackers from accessing it remotely.
  • Set up a strong and unique password for the router’s management interface.
  • Use a reliable antivirus software to protect against malware that may exploit this vulnerability.
  • Regularly monitor the device’s activity logs for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-20167 scanner - Command Injection vulnerability in Netgear RAX43 | S4E