Search Results (23 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-20168 1 Netgear 2 Rax43, Rax43 Firmware 2024-11-21 6.8 Medium
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute commands as the root user. These default credentials are admin:admin.
CVE-2021-20167 1 Netgear 2 Rax43, Rax43 Firmware 2024-11-21 8.0 High
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
CVE-2021-20166 1 Netgear 2 Rax43, Rax43 Firmware 2024-11-21 8.8 High
Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the applicaiton.