Metrics
No CVSS v4.0
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Adjacent Network
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.00122.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Netgear
Subscribe
|
Cbk40
Subscribe
Cbk40 Firmware
Subscribe
Cbk43
Subscribe
Cbk43 Firmware
Subscribe
Cbr40
Subscribe
Cbr40 Firmware
Subscribe
Ex6200
Subscribe
Ex6200 Firmware
Subscribe
Ex7700
Subscribe
Ex7700 Firmware
Subscribe
Ex8000
Subscribe
Ex8000 Firmware
Subscribe
Rbk12
Subscribe
Rbk12 Firmware
Subscribe
Rbk13
Subscribe
Rbk13 Firmware
Subscribe
Rbk14
Subscribe
Rbk14 Firmware
Subscribe
Rbk15
Subscribe
Rbk15 Firmware
Subscribe
Rbk20
Subscribe
Rbk20 Router Firmware
Subscribe
Rbk20 Satellite Firmware
Subscribe
Rbk20w
Subscribe
Rbk20w Firmware
Subscribe
Rbk22
Subscribe
Rbk22 Router Firmware
Subscribe
Rbk22 Satellite Firmware
Subscribe
Rbk23
Subscribe
Rbk23 Router Firmware
Subscribe
Rbk23 Satellite Firmware
Subscribe
Rbk23w
Subscribe
Rbk23w Firmware
Subscribe
Rbk30
Subscribe
Rbk30 Firmware
Subscribe
Rbk33
Subscribe
Rbk33 Firmware
Subscribe
Rbk40
Subscribe
Rbk40 Router Firmware
Subscribe
Rbk40 Satellite Firmware
Subscribe
Rbk43
Subscribe
Rbk43 Router Firmware
Subscribe
Rbk43 Satellite Firmware
Subscribe
Rbk43s
Subscribe
Rbk43s Router Firmware
Subscribe
Rbk43s Satellite Firmware
Subscribe
Rbk44
Subscribe
Rbk44 Router Firmware
Subscribe
Rbk44 Satellite Firmware
Subscribe
Rbk50
Subscribe
Rbk50 Firmware
Subscribe
Rbk50v
Subscribe
Rbk50v Firmware
Subscribe
Rbk52w
Subscribe
Rbk52w Firmware
Subscribe
Rbr10
Subscribe
Rbr10 Firmware
Subscribe
Rbr20
Subscribe
Rbr20 Firmware
Subscribe
Rbr40
Subscribe
Rbr40 Firmware
Subscribe
Rbr50
Subscribe
Rbr50 Firmware
Subscribe
Rbs10
Subscribe
Rbs10 Firmware
Subscribe
Rbs20
Subscribe
Rbs20 Firmware
Subscribe
Rbs40
Subscribe
Rbs40 Firmware
Subscribe
Rbs50
Subscribe
Rbs50 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
Configuration 24 [-]
| AND |
|
Configuration 25 [-]
| AND |
|
Configuration 26 [-]
| AND |
|
Configuration 27 [-]
| AND |
|
Configuration 28 [-]
| AND |
|
Configuration 29 [-]
| AND |
|
Configuration 30 [-]
| AND |
|
Configuration 31 [-]
| AND |
|
Configuration 32 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-20354 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11076. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-08-04T16:25:43.503Z
Reserved: 2020-10-27T00:00:00
Link: CVE-2020-27861
No data.
Status : Modified
Published: 2021-02-12T00:15:12.500
Modified: 2024-11-21T05:21:57.107
Link: CVE-2020-27861
No data.
OpenCVE Enrichment
No data.
EUVD