CVE-2022-27642
NETGEAR R6700v3 httpd Authentication Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-15854.
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the httpd service. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-22 CVE Reserved
- 2022-03-23 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-22-518 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | Cax80 Firmware Search vendor "Netgear" for product "Cax80 Firmware" | < 2.1.3.7 Search vendor "Netgear" for product "Cax80 Firmware" and version " < 2.1.3.7" | - |
Affected
| in | Netgear Search vendor "Netgear" | Cax80 Search vendor "Netgear" for product "Cax80" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Lax20 Firmware Search vendor "Netgear" for product "Lax20 Firmware" | < 1.1.6.34 Search vendor "Netgear" for product "Lax20 Firmware" and version " < 1.1.6.34" | - |
Affected
| in | Netgear Search vendor "Netgear" | Lax20 Search vendor "Netgear" for product "Lax20" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Mr60 Firmware Search vendor "Netgear" for product "Mr60 Firmware" | < 1.1.6.124 Search vendor "Netgear" for product "Mr60 Firmware" and version " < 1.1.6.124" | - |
Affected
| in | Netgear Search vendor "Netgear" | Mr60 Search vendor "Netgear" for product "Mr60" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Mr80 Firmware Search vendor "Netgear" for product "Mr80 Firmware" | < 1.1.6.14 Search vendor "Netgear" for product "Mr80 Firmware" and version " < 1.1.6.14" | - |
Affected
| in | Netgear Search vendor "Netgear" | Mr80 Search vendor "Netgear" for product "Mr80" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Ms60 Firmware Search vendor "Netgear" for product "Ms60 Firmware" | < 1.1.6.124 Search vendor "Netgear" for product "Ms60 Firmware" and version " < 1.1.6.124" | - |
Affected
| in | Netgear Search vendor "Netgear" | Ms60 Search vendor "Netgear" for product "Ms60" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Ms80 Firmware Search vendor "Netgear" for product "Ms80 Firmware" | < 1.1.6.14 Search vendor "Netgear" for product "Ms80 Firmware" and version " < 1.1.6.14" | - |
Affected
| in | Netgear Search vendor "Netgear" | Ms80 Search vendor "Netgear" for product "Ms80" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6400 Firmware Search vendor "Netgear" for product "R6400 Firmware" | < 1.0.1.78 Search vendor "Netgear" for product "R6400 Firmware" and version " < 1.0.1.78" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6400 Search vendor "Netgear" for product "R6400" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6400 Firmware Search vendor "Netgear" for product "R6400 Firmware" | < 1.0.4.126 Search vendor "Netgear" for product "R6400 Firmware" and version " < 1.0.4.126" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6400 Search vendor "Netgear" for product "R6400" | v2 Search vendor "Netgear" for product "R6400" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | R6700 Firmware Search vendor "Netgear" for product "R6700 Firmware" | < 1.0.4.126 Search vendor "Netgear" for product "R6700 Firmware" and version " < 1.0.4.126" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6700 Search vendor "Netgear" for product "R6700" | v3 Search vendor "Netgear" for product "R6700" and version "v3" | - |
Safe
|
Netgear Search vendor "Netgear" | R6900p Firmware Search vendor "Netgear" for product "R6900p Firmware" | < 1.3.3.148 Search vendor "Netgear" for product "R6900p Firmware" and version " < 1.3.3.148" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6900p Search vendor "Netgear" for product "R6900p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7000 Firmware Search vendor "Netgear" for product "R7000 Firmware" | < 1.0.11.134 Search vendor "Netgear" for product "R7000 Firmware" and version " < 1.0.11.134" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000 Search vendor "Netgear" for product "R7000" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7000p Firmware Search vendor "Netgear" for product "R7000p Firmware" | < 1.3.3.148 Search vendor "Netgear" for product "R7000p Firmware" and version " < 1.3.3.148" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000p Search vendor "Netgear" for product "R7000p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7850 Firmware Search vendor "Netgear" for product "R7850 Firmware" | < 1.0.5.84 Search vendor "Netgear" for product "R7850 Firmware" and version " < 1.0.5.84" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7850 Search vendor "Netgear" for product "R7850" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7900p Firmware Search vendor "Netgear" for product "R7900p Firmware" | < 1.4.3.88 Search vendor "Netgear" for product "R7900p Firmware" and version " < 1.4.3.88" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7900p Search vendor "Netgear" for product "R7900p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7960p Firmware Search vendor "Netgear" for product "R7960p Firmware" | < 1.4.3.88 Search vendor "Netgear" for product "R7960p Firmware" and version " < 1.4.3.88" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7960p Search vendor "Netgear" for product "R7960p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8000 Firmware Search vendor "Netgear" for product "R8000 Firmware" | < 1.0.4.84 Search vendor "Netgear" for product "R8000 Firmware" and version " < 1.0.4.84" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8000 Search vendor "Netgear" for product "R8000" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8000p Firmware Search vendor "Netgear" for product "R8000p Firmware" | < 1.4.3.88 Search vendor "Netgear" for product "R8000p Firmware" and version " < 1.4.3.88" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8000p Search vendor "Netgear" for product "R8000p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8500 Firmware Search vendor "Netgear" for product "R8500 Firmware" | < 1.0.2.158 Search vendor "Netgear" for product "R8500 Firmware" and version " < 1.0.2.158" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8500 Search vendor "Netgear" for product "R8500" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax15 Firmware Search vendor "Netgear" for product "Rax15 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax15 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax15 Search vendor "Netgear" for product "Rax15" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax20 Firmware Search vendor "Netgear" for product "Rax20 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax20 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax20 Search vendor "Netgear" for product "Rax20" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax200 Firmware Search vendor "Netgear" for product "Rax200 Firmware" | < 1.0.6.138 Search vendor "Netgear" for product "Rax200 Firmware" and version " < 1.0.6.138" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax200 Search vendor "Netgear" for product "Rax200" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax35 Firmware Search vendor "Netgear" for product "Rax35 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax35 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax35 Search vendor "Netgear" for product "Rax35" | v2 Search vendor "Netgear" for product "Rax35" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Rax38 Firmware Search vendor "Netgear" for product "Rax38 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax38 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax38 Search vendor "Netgear" for product "Rax38" | v2 Search vendor "Netgear" for product "Rax38" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Rax40 Firmware Search vendor "Netgear" for product "Rax40 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax40 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax40 Search vendor "Netgear" for product "Rax40" | v2 Search vendor "Netgear" for product "Rax40" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Rax42 Firmware Search vendor "Netgear" for product "Rax42 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax42 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax42 Search vendor "Netgear" for product "Rax42" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax43 Firmware Search vendor "Netgear" for product "Rax43 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax43 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax43 Search vendor "Netgear" for product "Rax43" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax45 Firmware Search vendor "Netgear" for product "Rax45 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax45 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax45 Search vendor "Netgear" for product "Rax45" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax48 Firmware Search vendor "Netgear" for product "Rax48 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax48 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax48 Search vendor "Netgear" for product "Rax48" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax50 Firmware Search vendor "Netgear" for product "Rax50 Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax50 Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax50 Search vendor "Netgear" for product "Rax50" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax50s Firmware Search vendor "Netgear" for product "Rax50s Firmware" | < 1.0.10.110 Search vendor "Netgear" for product "Rax50s Firmware" and version " < 1.0.10.110" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax50s Search vendor "Netgear" for product "Rax50s" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax75 Firmware Search vendor "Netgear" for product "Rax75 Firmware" | < 1.0.6.138 Search vendor "Netgear" for product "Rax75 Firmware" and version " < 1.0.6.138" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax75 Search vendor "Netgear" for product "Rax75" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax80 Firmware Search vendor "Netgear" for product "Rax80 Firmware" | < 1.0.6.138 Search vendor "Netgear" for product "Rax80 Firmware" and version " < 1.0.6.138" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax80 Search vendor "Netgear" for product "Rax80" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rs400 Firmware Search vendor "Netgear" for product "Rs400 Firmware" | < 1.5.1.86 Search vendor "Netgear" for product "Rs400 Firmware" and version " < 1.5.1.86" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rs400 Search vendor "Netgear" for product "Rs400" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7100lg Firmware Search vendor "Netgear" for product "R7100lg Firmware" | < 1.0.0.76 Search vendor "Netgear" for product "R7100lg Firmware" and version " < 1.0.0.76" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7100lg Search vendor "Netgear" for product "R7100lg" | - | - |
Safe
|