CVE-2021-31802
Netgear R7000 Backup.cgi Heap Overflow Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication. The vulnerability exists within the handling of an HTTP request. An attacker can leverage this to execute code as root. The problem is that a user-provided length value is trusted during a backup.cgi file upload. The attacker must add a
before the Content-Length header.
Los dispositivos NETGEAR R7000 versión 1.0.11.116, presentan un desbordamiento de búfer en la región heap de la memoria que es explotable desde la red local sin autenticación. La vulnerabilidad se presenta dentro del manejo de una petición HTTP. Un atacante puede aprovechar esto para ejecutar código como root. El problema es que un valor de longitud proporcionado por el usuario es confiable durante la carga de un archivo backup.cgi. El atacante debe agregar un
antes del encabezado Content-Length
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-25 CVE Reserved
- 2021-04-26 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://ssd-disclosure.com/ssd-advisory-netgear-nighthawk-r7000-httpd-preauth-rce | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.netgear.com/about/security | 2021-05-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | R7000 Firmware Search vendor "Netgear" for product "R7000 Firmware" | <= 1.0.11.116 Search vendor "Netgear" for product "R7000 Firmware" and version " <= 1.0.11.116" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000 Search vendor "Netgear" for product "R7000" | - | - |
Safe
|