// For flags

CVE-2021-40847

 

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR to obtain version information and updates to the circled daemon and its filtering database. However, database updates from NETGEAR are unsigned and downloaded via cleartext HTTP. As such, an attacker with the ability to perform a MitM attack on the device can respond to circled update requests with a crafted, compressed database file, the extraction of which gives the attacker the ability to overwrite executable files with attacker-controlled code. This affects R6400v2 1.0.4.106, R6700 1.0.2.16, R6700v3 1.0.4.106, R6900 1.0.2.16, R6900P 1.3.2.134, R7000 1.0.11.123, R7000P 1.3.2.134, R7850 1.0.5.68, R7900 1.0.4.38, R8000 1.0.4.68, and RS400 1.5.0.68.

El proceso de actualización del servicio de Control Parental Circle en varios routers de NETGEAR permite a atacantes remotos lograr una ejecución de código remota como root por medio de un ataque de tipo MitM. Mientras que los controles parentales en sí no están habilitados por defecto en los routers, el demonio de actualización de Circle, en forma de círculo, está habilitado por defecto. Este demonio se conecta a Circle y a NETGEAR para conseguir información sobre la versión y las actualizaciones del demonio Circle y su base de datos de filtrado. Sin embargo, las actualizaciones de la base de datos de NETGEAR no están firmadas y se descargan por medio de HTTP en texto sin cifrar. De este modo, un atacante con la capacidad de llevar a cabo un ataque de tipo MitM en el dispositivo puede responder a peticiones de actualización de Circle con un archivo de base de datos diseñado y comprimido, cuya extracción da al atacante la capacidad de sobrescribir archivos ejecutables con código controlado por el atacante. Esto afecta al R6400v2 versión 1.0.4.106, al R6700 versión 1.0.2.16, al R6700v3 versión 1.0.4.106, al R6900 versión 1.0.2.16, al R6900P versión 1.3.2.134, al R7000 versión 1.0.11.123, al R7000P versión 1.3.2.134, al R7850 versión 1.0.5.68, al R7900 versión 1.0.4.38, al R8000 versión 1.0.4.68 y al RS400 versión 1.5.0.68

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-09-10 CVE Reserved
  • 2021-09-21 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • 2024-11-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netgear
Search vendor "Netgear"
R6400v2 Firmware
Search vendor "Netgear" for product "R6400v2 Firmware"
1.0.4.106
Search vendor "Netgear" for product "R6400v2 Firmware" and version "1.0.4.106"
-
Affected
in Netgear
Search vendor "Netgear"
R6400v2
Search vendor "Netgear" for product "R6400v2"
--
Safe
Netgear
Search vendor "Netgear"
R6700 Firmware
Search vendor "Netgear" for product "R6700 Firmware"
1.0.2.16
Search vendor "Netgear" for product "R6700 Firmware" and version "1.0.2.16"
-
Affected
in Netgear
Search vendor "Netgear"
R6700
Search vendor "Netgear" for product "R6700"
--
Safe
Netgear
Search vendor "Netgear"
R6700v3 Firmware
Search vendor "Netgear" for product "R6700v3 Firmware"
1.0.4.106
Search vendor "Netgear" for product "R6700v3 Firmware" and version "1.0.4.106"
-
Affected
in Netgear
Search vendor "Netgear"
R6700v3
Search vendor "Netgear" for product "R6700v3"
--
Safe
Netgear
Search vendor "Netgear"
R6900 Firmware
Search vendor "Netgear" for product "R6900 Firmware"
1.0.2.16
Search vendor "Netgear" for product "R6900 Firmware" and version "1.0.2.16"
-
Affected
in Netgear
Search vendor "Netgear"
R6900
Search vendor "Netgear" for product "R6900"
--
Safe
Netgear
Search vendor "Netgear"
R6900p Firmware
Search vendor "Netgear" for product "R6900p Firmware"
1.3.2.134
Search vendor "Netgear" for product "R6900p Firmware" and version "1.3.2.134"
-
Affected
in Netgear
Search vendor "Netgear"
R6900p
Search vendor "Netgear" for product "R6900p"
--
Safe
Netgear
Search vendor "Netgear"
R7000 Firmware
Search vendor "Netgear" for product "R7000 Firmware"
1.0.11.123
Search vendor "Netgear" for product "R7000 Firmware" and version "1.0.11.123"
-
Affected
in Netgear
Search vendor "Netgear"
R7000
Search vendor "Netgear" for product "R7000"
--
Safe
Netgear
Search vendor "Netgear"
R7000p Firmware
Search vendor "Netgear" for product "R7000p Firmware"
1.3.2.134
Search vendor "Netgear" for product "R7000p Firmware" and version "1.3.2.134"
-
Affected
in Netgear
Search vendor "Netgear"
R7000p
Search vendor "Netgear" for product "R7000p"
--
Safe
Netgear
Search vendor "Netgear"
R7850 Firmware
Search vendor "Netgear" for product "R7850 Firmware"
1.0.5.68
Search vendor "Netgear" for product "R7850 Firmware" and version "1.0.5.68"
-
Affected
in Netgear
Search vendor "Netgear"
R7850
Search vendor "Netgear" for product "R7850"
--
Safe
Netgear
Search vendor "Netgear"
R7900 Firmware
Search vendor "Netgear" for product "R7900 Firmware"
1.0.4.38
Search vendor "Netgear" for product "R7900 Firmware" and version "1.0.4.38"
-
Affected
in Netgear
Search vendor "Netgear"
R7900
Search vendor "Netgear" for product "R7900"
--
Safe
Netgear
Search vendor "Netgear"
R8000 Firmware
Search vendor "Netgear" for product "R8000 Firmware"
1.0.4.68
Search vendor "Netgear" for product "R8000 Firmware" and version "1.0.4.68"
-
Affected
in Netgear
Search vendor "Netgear"
R8000
Search vendor "Netgear" for product "R8000"
--
Safe
Netgear
Search vendor "Netgear"
Rs400 Firmware
Search vendor "Netgear" for product "Rs400 Firmware"
1.5.0.68
Search vendor "Netgear" for product "Rs400 Firmware" and version "1.5.0.68"
-
Affected
in Netgear
Search vendor "Netgear"
Rs400
Search vendor "Netgear" for product "Rs400"
--
Safe