Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11076.
Published: 2021-02-11
Score: 8.8 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-20354 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11076.
History

No history.

Subscriptions

Netgear Cbk40 Cbk40 Firmware Cbk43 Cbk43 Firmware Cbr40 Cbr40 Firmware Ex6200 Ex6200 Firmware Ex7700 Ex7700 Firmware Ex8000 Ex8000 Firmware Rbk12 Rbk12 Firmware Rbk13 Rbk13 Firmware Rbk14 Rbk14 Firmware Rbk15 Rbk15 Firmware Rbk20 Rbk20 Router Firmware Rbk20 Satellite Firmware Rbk20w Rbk20w Firmware Rbk22 Rbk22 Router Firmware Rbk22 Satellite Firmware Rbk23 Rbk23 Router Firmware Rbk23 Satellite Firmware Rbk23w Rbk23w Firmware Rbk30 Rbk30 Firmware Rbk33 Rbk33 Firmware Rbk40 Rbk40 Router Firmware Rbk40 Satellite Firmware Rbk43 Rbk43 Router Firmware Rbk43 Satellite Firmware Rbk43s Rbk43s Router Firmware Rbk43s Satellite Firmware Rbk44 Rbk44 Router Firmware Rbk44 Satellite Firmware Rbk50 Rbk50 Firmware Rbk50v Rbk50v Firmware Rbk52w Rbk52w Firmware Rbr10 Rbr10 Firmware Rbr20 Rbr20 Firmware Rbr40 Rbr40 Firmware Rbr50 Rbr50 Firmware Rbs10 Rbs10 Firmware Rbs20 Rbs20 Firmware Rbs40 Rbs40 Firmware Rbs50 Rbs50 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-08-04T16:25:43.503Z

Reserved: 2020-10-27T00:00:00.000Z

Link: CVE-2020-27861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-12T00:15:12.500

Modified: 2024-11-21T05:21:57.107

Link: CVE-2020-27861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses