HIGH · 8.8

CVE-2021-27239

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to...

Vulnerability Description

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the upnpd service, which listens on UDP port 1900 by default. A crafted MX header field in an SSDP message can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11851.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NetgearD6220 Firmware< 1.0.0.68
NetgearD6220-
NetgearD6400 Firmware< 1.0.0.102
NetgearD6400-
NetgearD7000 Firmware< 1.0.0.66
NetgearD7000v2
NetgearD8500 Firmware< 1.0.3.60
NetgearD8500-
NetgearDc112A Firmware< 1.0.0.54
NetgearDc112A-
NetgearEx7000 Firmware< 1.0.1.94
NetgearEx7000-
NetgearEx7500 Firmware< 1.0.0.72
NetgearEx7500-
NetgearR6250 Firmware< 1.0.4.48
NetgearR6250-
NetgearR6300 Firmware< 1.0.4.50
NetgearR6300v2
NetgearR6400 Firmware< 1.0.1.68
NetgearR6400-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-27239?

CVE-2021-27239 is a vulnerability with a CVSS score of 8.8 (HIGH). This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to...

How severe is CVE-2021-27239?

CVE-2021-27239 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-27239?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear D6220 Firmware, Netgear D6220, Netgear D6400 Firmware, Netgear D6400, Netgear D7000 Firmware.