CVE-2021-27254
Summary
| CVE | CVE-2021-27254 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-05 20:15:00 UTC |
| Updated | 2022-04-25 17:48:00 UTC |
| Description | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-12287. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Br200 | - | All | All | All |
| Operating System | Netgear | Br200 Firmware | All | All | All | All |
| Hardware | Netgear | Br500 | - | All | All | All |
| Operating System | Netgear | Br500 Firmware | All | All | All | All |
| Hardware | Netgear | D7800 | - | All | All | All |
| Operating System | Netgear | D7800 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6100v2 | - | All | All | All |
| Operating System | Netgear | Ex6100v2 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6150v2 | - | All | All | All |
| Operating System | Netgear | Ex6150v2 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6250 | - | All | All | All |
| Operating System | Netgear | Ex6250 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6400 | - | All | All | All |
| Hardware | Netgear | Ex6400v2 | - | All | All | All |
| Operating System | Netgear | Ex6400v2 Firmware | All | All | All | All |
| Operating System | Netgear | Ex6400 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6410 | - | All | All | All |
| Operating System | Netgear | Ex6410 Firmware | All | All | All | All |
| Hardware | Netgear | Ex6420 | - | All | All | All |
| Operating System | Netgear | Ex6420 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7300 | - | All | All | All |
| Hardware | Netgear | Ex7300v2 | - | All | All | All |
| Operating System | Netgear | Ex7300v2 Firmware | All | All | All | All |
| Operating System | Netgear | Ex7300 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7320 | - | All | All | All |
| Operating System | Netgear | Ex7320 Firmware | All | All | All | All |
| Hardware | Netgear | Ex7700 | - | All | All | All |
| Operating System | Netgear | Ex7700 Firmware | All | All | All | All |
| Hardware | Netgear | Ex8000 | - | All | All | All |
| Operating System | Netgear | Ex8000 Firmware | All | All | All | All |
| Hardware | Netgear | Lbr20 | - | All | All | All |
| Operating System | Netgear | Lbr20 Firmware | All | All | All | All |
| Hardware | Netgear | R7800 | - | All | All | All |
| Operating System | Netgear | R7800 Firmware | All | All | All | All |
| Hardware | Netgear | R8900 | - | All | All | All |
| Operating System | Netgear | R8900 Firmware | All | All | All | All |
| Hardware | Netgear | R9000 | - | All | All | All |
| Operating System | Netgear | R9000 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk12 | - | All | All | All |
| Operating System | Netgear | Rbk12 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk13 | - | All | All | All |
| Operating System | Netgear | Rbk13 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk14 | - | All | All | All |
| Operating System | Netgear | Rbk14 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk15 | - | All | All | All |
| Operating System | Netgear | Rbk15 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk20 | - | All | All | All |
| Operating System | Netgear | Rbk20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk23 | - | All | All | All |
| Operating System | Netgear | Rbk23 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk40 | - | All | All | All |
| Operating System | Netgear | Rbk40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk43 | - | All | All | All |
| Hardware | Netgear | Rbk43s | - | All | All | All |
| Operating System | Netgear | Rbk43s Firmware | All | All | All | All |
| Operating System | Netgear | Rbk43 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk44 | - | All | All | All |
| Operating System | Netgear | Rbk44 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk50 | - | All | All | All |
| Operating System | Netgear | Rbk50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk53 | - | All | All | All |
| Operating System | Netgear | Rbk53 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr10 | - | All | All | All |
| Operating System | Netgear | Rbr10 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr20 | - | All | All | All |
| Operating System | Netgear | Rbr20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr40 | - | All | All | All |
| Operating System | Netgear | Rbr40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr50 | - | All | All | All |
| Operating System | Netgear | Rbr50 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs10 | - | All | All | All |
| Operating System | Netgear | Rbs10 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs20 | - | All | All | All |
| Operating System | Netgear | Rbs20 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs40 | - | All | All | All |
| Operating System | Netgear | Rbs40 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs50 | - | All | All | All |
| Hardware | Netgear | Rbs50y | - | All | All | All |
| Operating System | Netgear | Rbs50y Firmware | All | All | All | All |
| Operating System | Netgear | Rbs50 Firmware | All | All | All | All |
| Hardware | Netgear | Xr450 | - | All | All | All |
| Operating System | Netgear | Xr450 Firmware | All | All | All | All |
| Hardware | Netgear | Xr500 | - | All | All | All |
| Operating System | Netgear | Xr500 Firmware | All | All | All | All |
| Hardware | Netgear | Xr700 | - | All | All | All |
| Operating System | Netgear | Xr700 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Multiple Vulnerabilities on Some Routers, Satellites, and Extenders | Answer | NETGEAR Support | N/A | kb.netgear.com | Patch, Vendor Advisory |
| ZDI-21-252 | Zero Day Initiative | N/A | www.zerodayinitiative.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.