NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.
| Software | From | Fixed in |
|---|---|---|
| netgear / r8500_firmware | 1.0.2.158 | 1.0.2.158.x |