CVE-2022-27643
NETGEAR R6700v3 upnpd Buffer Overflow Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process does not properly validate the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15692.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process does not properly validate the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-22 CVE Reserved
- 2022-03-23 CVE Published
- 2024-08-03 CVE Updated
- 2024-09-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-22-519 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | R6400 Firmware Search vendor "Netgear" for product "R6400 Firmware" | < 1.0.1.78 Search vendor "Netgear" for product "R6400 Firmware" and version " < 1.0.1.78" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6400 Search vendor "Netgear" for product "R6400" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6400 Firmware Search vendor "Netgear" for product "R6400 Firmware" | < 1.0.4.126 Search vendor "Netgear" for product "R6400 Firmware" and version " < 1.0.4.126" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6400 Search vendor "Netgear" for product "R6400" | v2 Search vendor "Netgear" for product "R6400" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | R6700 Firmware Search vendor "Netgear" for product "R6700 Firmware" | < 1.0.4.126 Search vendor "Netgear" for product "R6700 Firmware" and version " < 1.0.4.126" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6700 Search vendor "Netgear" for product "R6700" | v3 Search vendor "Netgear" for product "R6700" and version "v3" | - |
Safe
|
Netgear Search vendor "Netgear" | R6900p Firmware Search vendor "Netgear" for product "R6900p Firmware" | < 1.3.3.148 Search vendor "Netgear" for product "R6900p Firmware" and version " < 1.3.3.148" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6900p Search vendor "Netgear" for product "R6900p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7000 Firmware Search vendor "Netgear" for product "R7000 Firmware" | < 1.0.11.134 Search vendor "Netgear" for product "R7000 Firmware" and version " < 1.0.11.134" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000 Search vendor "Netgear" for product "R7000" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7000p Firmware Search vendor "Netgear" for product "R7000p Firmware" | < 1.3.3.148 Search vendor "Netgear" for product "R7000p Firmware" and version " < 1.3.3.148" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7000p Search vendor "Netgear" for product "R7000p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7850 Firmware Search vendor "Netgear" for product "R7850 Firmware" | < 1.0.5.84 Search vendor "Netgear" for product "R7850 Firmware" and version " < 1.0.5.84" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7850 Search vendor "Netgear" for product "R7850" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7900p Firmware Search vendor "Netgear" for product "R7900p Firmware" | < 1.4.3.88 Search vendor "Netgear" for product "R7900p Firmware" and version " < 1.4.3.88" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7900p Search vendor "Netgear" for product "R7900p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7960p Firmware Search vendor "Netgear" for product "R7960p Firmware" | < 1.4.3.88 Search vendor "Netgear" for product "R7960p Firmware" and version " < 1.4.3.88" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7960p Search vendor "Netgear" for product "R7960p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8000 Firmware Search vendor "Netgear" for product "R8000 Firmware" | < 1.0.4.84 Search vendor "Netgear" for product "R8000 Firmware" and version " < 1.0.4.84" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8000 Search vendor "Netgear" for product "R8000" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8000p Firmware Search vendor "Netgear" for product "R8000p Firmware" | < 1.4.3.88 Search vendor "Netgear" for product "R8000p Firmware" and version " < 1.4.3.88" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8000p Search vendor "Netgear" for product "R8000p" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R8500 Firmware Search vendor "Netgear" for product "R8500 Firmware" | < 1.0.2.158 Search vendor "Netgear" for product "R8500 Firmware" and version " < 1.0.2.158" | - |
Affected
| in | Netgear Search vendor "Netgear" | R8500 Search vendor "Netgear" for product "R8500" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax200 Firmware Search vendor "Netgear" for product "Rax200 Firmware" | < 1.0.6.138 Search vendor "Netgear" for product "Rax200 Firmware" and version " < 1.0.6.138" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax200 Search vendor "Netgear" for product "Rax200" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax75 Firmware Search vendor "Netgear" for product "Rax75 Firmware" | < 1.0.6.138 Search vendor "Netgear" for product "Rax75 Firmware" and version " < 1.0.6.138" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax75 Search vendor "Netgear" for product "Rax75" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rax80 Firmware Search vendor "Netgear" for product "Rax80 Firmware" | < 1.0.6.138 Search vendor "Netgear" for product "Rax80 Firmware" and version " < 1.0.6.138" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rax80 Search vendor "Netgear" for product "Rax80" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Rs400 Firmware Search vendor "Netgear" for product "Rs400 Firmware" | < 1.5.1.86 Search vendor "Netgear" for product "Rs400 Firmware" and version " < 1.5.1.86" | - |
Affected
| in | Netgear Search vendor "Netgear" | Rs400 Search vendor "Netgear" for product "Rs400" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R7100lg Firmware Search vendor "Netgear" for product "R7100lg Firmware" | < 1.0.0.76 Search vendor "Netgear" for product "R7100lg Firmware" and version " < 1.0.0.76" | - |
Affected
| in | Netgear Search vendor "Netgear" | R7100lg Search vendor "Netgear" for product "R7100lg" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Wndr3400 Firmware Search vendor "Netgear" for product "Wndr3400 Firmware" | < 1.0.1.44 Search vendor "Netgear" for product "Wndr3400 Firmware" and version " < 1.0.1.44" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wndr3400 Search vendor "Netgear" for product "Wndr3400" | v3 Search vendor "Netgear" for product "Wndr3400" and version "v3" | - |
Safe
|
Netgear Search vendor "Netgear" | Wnr3500l Firmware Search vendor "Netgear" for product "Wnr3500l Firmware" | < 1.2.0.72 Search vendor "Netgear" for product "Wnr3500l Firmware" and version " < 1.2.0.72" | - |
Affected
| in | Netgear Search vendor "Netgear" | Wnr3500l Search vendor "Netgear" for product "Wnr3500l" | v2 Search vendor "Netgear" for product "Wnr3500l" and version "v2" | - |
Safe
|
Netgear Search vendor "Netgear" | Xr300 Firmware Search vendor "Netgear" for product "Xr300 Firmware" | < 1.0.3.72 Search vendor "Netgear" for product "Xr300 Firmware" and version " < 1.0.3.72" | - |
Affected
| in | Netgear Search vendor "Netgear" | Xr300 Search vendor "Netgear" for product "Xr300" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Dc112a Firmware Search vendor "Netgear" for product "Dc112a Firmware" | < 1.0.0.64 Search vendor "Netgear" for product "Dc112a Firmware" and version " < 1.0.0.64" | - |
Affected
| in | Netgear Search vendor "Netgear" | Dc112a Search vendor "Netgear" for product "Dc112a" | - | - |
Safe
|
Netgear Search vendor "Netgear" | D6220 Firmware Search vendor "Netgear" for product "D6220 Firmware" | < 1.0.0.80 Search vendor "Netgear" for product "D6220 Firmware" and version " < 1.0.0.80" | - |
Affected
| in | Netgear Search vendor "Netgear" | D6220 Search vendor "Netgear" for product "D6220" | - | - |
Safe
|
Netgear Search vendor "Netgear" | D6400 Firmware Search vendor "Netgear" for product "D6400 Firmware" | < 1.0.0.114 Search vendor "Netgear" for product "D6400 Firmware" and version " < 1.0.0.114" | - |
Affected
| in | Netgear Search vendor "Netgear" | D6400 Search vendor "Netgear" for product "D6400" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Ex3700 Firmware Search vendor "Netgear" for product "Ex3700 Firmware" | < 1.0.0.96 Search vendor "Netgear" for product "Ex3700 Firmware" and version " < 1.0.0.96" | - |
Affected
| in | Netgear Search vendor "Netgear" | Ex3700 Search vendor "Netgear" for product "Ex3700" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Ex3800 Firmware Search vendor "Netgear" for product "Ex3800 Firmware" | < 1.0.0.96 Search vendor "Netgear" for product "Ex3800 Firmware" and version " < 1.0.0.96" | - |
Affected
| in | Netgear Search vendor "Netgear" | Ex3800 Search vendor "Netgear" for product "Ex3800" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Ex6120 Firmware Search vendor "Netgear" for product "Ex6120 Firmware" | < 1.0.0.68 Search vendor "Netgear" for product "Ex6120 Firmware" and version " < 1.0.0.68" | - |
Affected
| in | Netgear Search vendor "Netgear" | Ex6120 Search vendor "Netgear" for product "Ex6120" | - | - |
Safe
|
Netgear Search vendor "Netgear" | Ex6130 Firmware Search vendor "Netgear" for product "Ex6130 Firmware" | < 1.0.0.48 Search vendor "Netgear" for product "Ex6130 Firmware" and version " < 1.0.0.48" | - |
Affected
| in | Netgear Search vendor "Netgear" | Ex6130 Search vendor "Netgear" for product "Ex6130" | - | - |
Safe
|
Netgear Search vendor "Netgear" | D7000v2 Firmware Search vendor "Netgear" for product "D7000v2 Firmware" | < 1.0.0.80 Search vendor "Netgear" for product "D7000v2 Firmware" and version " < 1.0.0.80" | - |
Affected
| in | Netgear Search vendor "Netgear" | D7000v2 Search vendor "Netgear" for product "D7000v2" | - | - |
Safe
|