CVE-2021-27239
Summary
| CVE | CVE-2021-27239 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-29 21:15:00 UTC |
| Updated | 2021-04-02 14:03:00 UTC |
| Description | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the upnpd service, which listens on UDP port 1900 by default. A crafted MX header field in an SSDP message can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11851. |
Risk And Classification
Problem Types: CWE-121
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | D6220 | - | All | All | All |
| Operating System | Netgear | D6220 Firmware | All | All | All | All |
| Hardware | Netgear | D6400 | - | All | All | All |
| Operating System | Netgear | D6400 Firmware | All | All | All | All |
| Hardware | Netgear | D7000 | v2 | All | All | All |
| Operating System | Netgear | D7000 Firmware | All | All | All | All |
| Hardware | Netgear | D8500 | - | All | All | All |
| Operating System | Netgear | D8500 Firmware | All | All | All | All |
| Hardware | Netgear | Dc112a | - | All | All | All |
| Operating System | Netgear | Dc112a Firmware | All | All | All | All |
| Hardware | Netgear | Ex7000 | - | All | All | All |
| Operating System | Netgear | Ex7000 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7500 | - | All | All | All |
| Operating System | Netgear | Ex7500 Firmware | All | All | All | All |
| Hardware | Netgear | R6250 | - | All | All | All |
| Operating System | Netgear | R6250 Firmware | All | All | All | All |
| Hardware | Netgear | R6300 | v2 | All | All | All |
| Operating System | Netgear | R6300 Firmware | All | All | All | All |
| Hardware | Netgear | R6400 | - | All | All | All |
| Hardware | Netgear | R6400 | v2 | All | All | All |
| Operating System | Netgear | R6400 Firmware | All | All | All | All |
| Hardware | Netgear | R6700 | v3 | All | All | All |
| Operating System | Netgear | R6700 Firmware | All | All | All | All |
| Hardware | Netgear | R6900p | - | All | All | All |
| Operating System | Netgear | R6900p Firmware | All | All | All | All |
| Hardware | Netgear | R7000 | - | All | All | All |
| Hardware | Netgear | R7000p | - | All | All | All |
| Operating System | Netgear | R7000p Firmware | All | All | All | All |
| Operating System | Netgear | R7000 Firmware | All | All | All | All |
| Hardware | Netgear | R7100lg | - | All | All | All |
| Operating System | Netgear | R7100lg Firmware | All | All | All | All |
| Hardware | Netgear | R7850 | - | All | All | All |
| Operating System | Netgear | R7850 Firmware | All | All | All | All |
| Hardware | Netgear | R7900 | - | All | All | All |
| Hardware | Netgear | R7900p | - | All | All | All |
| Operating System | Netgear | R7900p Firmware | All | All | All | All |
| Operating System | Netgear | R7900 Firmware | All | All | All | All |
| Hardware | Netgear | R7960p | - | All | All | All |
| Operating System | Netgear | R7960p Firmware | All | All | All | All |
| Hardware | Netgear | R8000 | - | All | All | All |
| Hardware | Netgear | R8000p | - | All | All | All |
| Operating System | Netgear | R8000p Firmware | All | All | All | All |
| Operating System | Netgear | R8000 Firmware | All | All | All | All |
| Hardware | Netgear | R8300 | - | All | All | All |
| Operating System | Netgear | R8300 Firmware | All | All | All | All |
| Hardware | Netgear | R8500 | - | All | All | All |
| Operating System | Netgear | R8500 Firmware | All | All | All | All |
| Hardware | Netgear | Rax200 | - | All | All | All |
| Operating System | Netgear | Rax200 Firmware | All | All | All | All |
| Hardware | Netgear | Rax75 | - | All | All | All |
| Operating System | Netgear | Rax75 Firmware | All | All | All | All |
| Hardware | Netgear | Rax80 | - | All | All | All |
| Operating System | Netgear | Rax80 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr750 | - | All | All | All |
| Operating System | Netgear | Rbr750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr850 | - | All | All | All |
| Operating System | Netgear | Rbr850 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs40v | - | All | All | All |
| Operating System | Netgear | Rbs40v Firmware | All | All | All | All |
| Hardware | Netgear | Rbs750 | - | All | All | All |
| Operating System | Netgear | Rbs750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs850 | - | All | All | All |
| Operating System | Netgear | Rbs850 Firmware | All | All | All | All |
| Hardware | Netgear | Rs400 | - | All | All | All |
| Operating System | Netgear | Rs400 Firmware | All | All | All | All |
| Hardware | Netgear | Wndr3400 | v3 | All | All | All |
| Operating System | Netgear | Wndr3400 Firmware | All | All | All | All |
| Hardware | Netgear | Wnr3500l | v2 | All | All | All |
| Operating System | Netgear | Wnr3500l Firmware | All | All | All | All |
| Hardware | Netgear | Xr300 | - | All | All | All |
| Operating System | Netgear | Xr300 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ZDI-21-206 | Zero Day Initiative | N/A | www.zerodayinitiative.com | |
| Security Advisory for Stack-based Buffer Overflow Remote Code Execution Vulnerability on Some Routers, PSV-2020-0432 | Answer | NETGEAR Support | N/A | kb.netgear.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.