Authentication Bypass Vulnerability in NETGEAR R6700 Routers
CVE-2020-10923
6.5MEDIUM
Summary
A vulnerability in the UPnP service of NETGEAR R6700 routers allows network-adjacent attackers to bypass authentication. This flaw, found in versions V1.0.4.84_10.0.58, enables attackers to exploit crafted UPnP messages sent to TCP port 5000. Such exploitation can facilitate unauthorized actions, potentially leading to arbitrary code execution in the context of root. Users should ensure their devices are updated to mitigate the risk posed by this vulnerability.
Affected Version(s)
R6700 V1.0.4.84_10.0.58
References
EPSS Score
43% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pedro Ribeiro and Radek Domanski of Team Flashback