CVE-2021-34865
Summary
| CVE | CVE-2021-34865 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-25 16:15:00 UTC |
| Updated | 2022-10-27 11:53:00 UTC |
| Description | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13313. |
Risk And Classification
Problem Types: CWE-697
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Ac2100 | - | All | All | All |
| Operating System | Netgear | Ac2100 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2400 | - | All | All | All |
| Operating System | Netgear | Ac2400 Firmware | All | All | All | All |
| Hardware | Netgear | Ac2600 | - | All | All | All |
| Operating System | Netgear | Ac2600 Firmware | All | All | All | All |
| Hardware | Netgear | D7000v1 | - | All | All | All |
| Operating System | Netgear | D7000v1 Firmware | All | All | All | All |
| Hardware | Netgear | R6220 | - | All | All | All |
| Operating System | Netgear | R6220 Firmware | All | All | All | All |
| Hardware | Netgear | R6230 | - | All | All | All |
| Operating System | Netgear | R6230 Firmware | All | All | All | All |
| Hardware | Netgear | R6260 | - | All | All | All |
| Operating System | Netgear | R6260 Firmware | All | All | All | All |
| Hardware | Netgear | R6330 | - | All | All | All |
| Operating System | Netgear | R6330 Firmware | All | All | All | All |
| Hardware | Netgear | R6350 | - | All | All | All |
| Operating System | Netgear | R6350 Firmware | All | All | All | All |
| Hardware | Netgear | R6700v2 | - | All | All | All |
| Operating System | Netgear | R6700v2 Firmware | All | All | All | All |
| Hardware | Netgear | R6800 | - | All | All | All |
| Operating System | Netgear | R6800 Firmware | All | All | All | All |
| Hardware | Netgear | R6850 | - | All | All | All |
| Operating System | Netgear | R6850 Firmware | All | All | All | All |
| Hardware | Netgear | R6900v2 | - | All | All | All |
| Operating System | Netgear | R6900v2 Firmware | All | All | All | All |
| Hardware | Netgear | R7200 | - | All | All | All |
| Operating System | Netgear | R7200 Firmware | All | All | All | All |
| Hardware | Netgear | R7350 | - | All | All | All |
| Operating System | Netgear | R7350 Firmware | All | All | All | All |
| Hardware | Netgear | R7400 | - | All | All | All |
| Operating System | Netgear | R7400 Firmware | All | All | All | All |
| Hardware | Netgear | R7450 | - | All | All | All |
| Operating System | Netgear | R7450 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Authentication Bypass Vulnerability on Some Routers, PSV-2021-0083 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| ZDI-21-1051 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.