Arbitrary Code Execution Vulnerability in NETGEAR Routers
CVE-2020-10928
8.4HIGH
Summary
This vulnerability enables network-adjacent attackers to execute arbitrary code on affected NETGEAR R6700 routers. The flaw arises from improper validation of user-supplied data lengths during string table file uploads, leading to uncontrolled buffer copying. This lack of stringent checks allows an attacker to run malicious code within the web server’s context, posing significant risks to network integrity. Authentication is not necessary for exploitation, making this vulnerability particularly concerning for affected users.
Affected Version(s)
R6700 V1.0.4.84_10.0.58
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
d4rkn3ss from VNPT ISC