CVE-2020-27867
Summary
| CVE | CVE-2020-27867 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-12 00:15:00 UTC |
| Updated | 2021-03-26 19:37:00 UTC |
| Description | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. When parsing the funjsq_access_token parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11653. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Hardware | Netgear | R6020 | - | All | All | All |
| Hardware | Netgear | R6020 | - | All | All | All |
| Operating System | Netgear | R6020 Firmware | All | All | All | All |
| Operating System | Netgear | R6020 Firmware | All | All | All | All |
| Hardware | Netgear | R6080 | - | All | All | All |
| Hardware | Netgear | R6080 | - | All | All | All |
| Operating System | Netgear | R6080 Firmware | All | All | All | All |
| Operating System | Netgear | R6080 Firmware | All | All | All | All |
| Hardware | Netgear | R6120 | - | All | All | All |
| Hardware | Netgear | R6120 | - | All | All | All |
| Operating System | Netgear | R6120 Firmware | All | All | All | All |
| Operating System | Netgear | R6120 Firmware | All | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Hardware | Netgear | R6700 | v2 | All | All | All |
| Hardware | Netgear | R6700 | v2 | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Hardware | Netgear | R6900 | v2 | All | All | All |
| Hardware | Netgear | R6900 | v2 | All | All | All |
| Operating System | Netgear | R6900 Firmware | All | All | All | All |
| Operating System | Netgear | R6900 Firmware | All | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-20-1423 | Zero Day Initiative | MISC | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| Security Advisory for Password Recovery Vulnerabilities on Some Routers | Answer | NETGEAR Support | MISC | kb.netgear.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.