CVE-2020-27872
Summary
| CVE | CVE-2020-27872 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-04 17:15:00 UTC |
| Updated | 2021-02-08 20:12:00 UTC |
| Description | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from improper state tracking in the password recovery process. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11365. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Hardware | Netgear | R6020 | - | All | All | All |
| Hardware | Netgear | R6020 | - | All | All | All |
| Operating System | Netgear | R6020 Firmware | All | All | All | All |
| Operating System | Netgear | R6020 Firmware | All | All | All | All |
| Hardware | Netgear | R6080 | - | All | All | All |
| Hardware | Netgear | R6080 | - | All | All | All |
| Operating System | Netgear | R6080 Firmware | All | All | All | All |
| Operating System | Netgear | R6080 Firmware | All | All | All | All |
| Hardware | Netgear | R6120 | - | All | All | All |
| Hardware | Netgear | R6120 | - | All | All | All |
| Operating System | Netgear | R6120 Firmware | All | All | All | All |
| Operating System | Netgear | R6120 Firmware | All | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Hardware | Netgear | R6700 | v2 | All | All | All |
| Hardware | Netgear | R6700 | v2 | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Hardware | Netgear | R6900 | v2 | All | All | All |
| Hardware | Netgear | R6900 | v2 | All | All | All |
| Operating System | Netgear | R6900 Firmware | All | All | All | All |
| Operating System | Netgear | R6900 Firmware | All | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-21-071 | Zero Day Initiative | N/A | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| Security Advisory for Password Recovery Vulnerabilities on Some Routers | Answer | NETGEAR Support | N/A | kb.netgear.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.