Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_bind.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12303.
Published: 2021-04-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-14018 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_bind.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12303.
History

No history.

Subscriptions

Netgear Br200 Br200 Firmware Br500 Br500 Firmware D7800 D7800 Firmware Ex6100 Ex6100v2 Firmware Ex6150 Ex6150 Firmware Ex6250 Ex6250 Firmware Ex6400 Ex6400 Firmware Ex6400v2 Firmware Ex6410 Ex6410 Firmware Ex6420 Ex6420 Firmware Ex7300 Ex7300 Firmware Ex7300v2 Firmware Ex7320 Ex7320 Firmware Ex7700 Ex7700 Firmware Ex8000 Ex8000 Firmware Lbr20 Lbr20 Firmware R7800 R7800 Firmware R8900 R8900 Firmware R9000 R9000 Firmware Rbk12 Rbk12 Firmware Rbk13 Rbk13 Firmware Rbk14 Rbk14 Firmware Rbk15 Rbk15 Firmware Rbk20 Rbk20 Firmware Rbk23 Rbk23 Firmware Rbk40 Rbk40 Firmware Rbk43 Rbk43 Firmware Rbk43s Rbk43s Firmware Rbk44 Rbk44 Firmware Rbk50 Rbk50 Firmware Rbk53 Rbk53 Firmware Rbr10 Rbr10 Firmware Rbr20 Rbr20 Firmware Rbr40 Rbr40 Firmware Rbr50 Rbr50 Firmware Rbs10 Rbs10 Firmware Rbs20 Rbs20 Firmware Rbs40 Rbs40 Firmware Rbs50 Rbs50 Firmware Rbs50y Rbs50y Firmware Xr450 Xr450 Firmware Xr500 Xr500 Firmware Xr700 Xr700 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-08-03T20:48:16.037Z

Reserved: 2021-02-16T00:00:00.000Z

Link: CVE-2021-27253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-14T16:15:13.797

Modified: 2024-11-21T05:57:41.613

Link: CVE-2021-27253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses