Remote Code Execution Vulnerability in NETGEAR Nighthawk R7000 Router
CVE-2020-28041
6.5MEDIUM
Summary
The SIP ALG feature in NETGEAR's Nighthawk R7000 router may allow remote attackers to exploit NAT Slipstreaming. By directing a victim to a malicious website through a modern browser, attackers can communicate with internal TCP and UDP services on the victim's network. This vulnerability arises from improper handling of IP packets containing specific substrings, which allows unauthorized access to the internal network without the victim's direct interaction.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved