CVE-2021-40847
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR to obtain version information and updates to the circled daemon and its filtering database. However, database updates from NETGEAR are unsigned and downloaded via cleartext HTTP. As such, an attacker with the ability to perform a MitM attack on the device can respond to circled update requests with a crafted, compressed database file, the extraction of which gives the attacker the ability to overwrite executable files with attacker-controlled code. This affects R6400v2 1.0.4.106, R6700 1.0.2.16, R6700v3 1.0.4.106, R6900 1.0.2.16, R6900P 1.3.2.134, R7000 1.0.11.123, R7000P 1.3.2.134, R7850 1.0.5.68, R7900 1.0.4.38, R8000 1.0.4.68, and RS400 1.5.0.68.
El proceso de actualización del servicio de Control Parental Circle en varios routers de NETGEAR permite a atacantes remotos lograr una ejecución de código remota como root por medio de un ataque de tipo MitM. Mientras que los controles parentales en sí no están habilitados por defecto en los routers, el demonio de actualización de Circle, en forma de círculo, está habilitado por defecto. Este demonio se conecta a Circle y a NETGEAR para conseguir información sobre la versión y las actualizaciones del demonio Circle y su base de datos de filtrado. Sin embargo, las actualizaciones de la base de datos de NETGEAR no están firmadas y se descargan por medio de HTTP en texto sin cifrar. De este modo, un atacante con la capacidad de llevar a cabo un ataque de tipo MitM en el dispositivo puede responder a peticiones de actualización de Circle con un archivo de base de datos diseñado y comprimido, cuya extracción da al atacante la capacidad de sobrescribir archivos ejecutables con código controlado por el atacante. Esto afecta al R6400v2 versión 1.0.4.106, al R6700 versión 1.0.2.16, al R6700v3 versión 1.0.4.106, al R6900 versión 1.0.2.16, al R6900P versión 1.3.2.134, al R7000 versión 1.0.11.123, al R7000P versión 1.3.2.134, al R7850 versión 1.0.5.68, al R7900 versión 1.0.4.38, al R8000 versión 1.0.4.68 y al RS400 versión 1.5.0.68
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-10 CVE Reserved
- 2021-09-21 CVE Published
- 2024-07-02 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://blog.grimm-co.com/2021/09/mama-always-told-me-not-to-trust.html | 2024-08-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | R6400v2 Firmware Search vendor "Netgear" for product "R6400v2 Firmware" | 1.0.4.106 Search vendor "Netgear" for product "R6400v2 Firmware" and version "1.0.4.106" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6400v2 Search vendor "Netgear" for product "R6400v2" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6700 Firmware Search vendor "Netgear" for product "R6700 Firmware" | 1.0.2.16 Search vendor "Netgear" for product "R6700 Firmware" and version "1.0.2.16" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6700 Search vendor "Netgear" for product "R6700" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6700v3 Firmware Search vendor "Netgear" for product "R6700v3 Firmware" | 1.0.4.106 Search vendor "Netgear" for product "R6700v3 Firmware" and version "1.0.4.106" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6700v3 Search vendor "Netgear" for product "R6700v3" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6900 Firmware Search vendor "Netgear" for product "R6900 Firmware" | 1.0.2.16 Search vendor "Netgear" for product "R6900 Firmware" and version "1.0.2.16" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6900 Search vendor "Netgear" for product "R6900" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6900p Firmware Search vendor "Netgear" for product "R6900p Firmware" | 1.3.2.134 Search vendor "Netgear" for product "R6900p Firmware" and version "1.3.2.134" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6900p Search vendor "Netgear" for product "R6900p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7000 Firmware Search vendor "Netgear" for product "R7000 Firmware" | 1.0.11.123 Search vendor "Netgear" for product "R7000 Firmware" and version "1.0.11.123" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000 Search vendor "Netgear" for product "R7000" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7000p Firmware Search vendor "Netgear" for product "R7000p Firmware" | 1.3.2.134 Search vendor "Netgear" for product "R7000p Firmware" and version "1.3.2.134" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000p Search vendor "Netgear" for product "R7000p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7850 Firmware Search vendor "Netgear" for product "R7850 Firmware" | 1.0.5.68 Search vendor "Netgear" for product "R7850 Firmware" and version "1.0.5.68" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7850 Search vendor "Netgear" for product "R7850" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7900 Firmware Search vendor "Netgear" for product "R7900 Firmware" | 1.0.4.38 Search vendor "Netgear" for product "R7900 Firmware" and version "1.0.4.38" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7900 Search vendor "Netgear" for product "R7900" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8000 Firmware Search vendor "Netgear" for product "R8000 Firmware" | 1.0.4.68 Search vendor "Netgear" for product "R8000 Firmware" and version "1.0.4.68" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8000 Search vendor "Netgear" for product "R8000" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rs400 Firmware Search vendor "Netgear" for product "Rs400 Firmware" | 1.5.0.68 Search vendor "Netgear" for product "Rs400 Firmware" and version "1.5.0.68" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rs400 Search vendor "Netgear" for product "Rs400" | - | - |
Safe
|