NETGEAR Alert
8499Warning Date
Severity Level
Warning Number
Target Sector
23 March, 2023
● High
2023-5512
All
NETGEAR has released security update to address several vulnerabilities in the following products:
- Orbi WiFi Systems
- RBR750 fixed in firmware version 4.6.14.3
- RBR840 fixed in firmware version 4.6.14.3
- RBR850 fixed in firmware version 4.6.14.3
- RBR860 fixed in firmware version 7.2.4.5
- RBRE950 fixed in firmware version 6.3.7.10
- RBRE960 fixed in firmware version 6.3.7.10
- RBS750 fixed in firmware version 4.6.14.3
- RBS840 fixed in firmware version 4.6.14.3
- RBS850 fixed in firmware version 4.6.14.3
- RBS860 fixed in firmware version 7.2.4.5
- RBSE950 fixed in firmware version 6.3.7.10
- RBSE960 fixed in firmware version 6.3.7.10
An attacker could exploit these vulnerabilities by doing a Command Injection.
The CERT team encourages users to review NETGEAR security advisory and apply the necessary updates:
- https://kb.netgear.com/000065417/Security-Advisory-for-Command-Injection-on-Some-Orbi-WiFi-Systems-PSV-2022-0187?article=000065417
- https://kb.netgear.com/000065424/Security-Advisory-for-Command-Injection-on-Some-Orbi-WiFi-Systems-PSV-2022-0188?article=000065424