Arbitrary Code Execution Vulnerability in NETGEAR Nighthawk Router
CVE-2021-27253
8.8HIGH
Summary
A vulnerability exists in the NETGEAR Nighthawk R7800 that enables network-adjacent attackers to execute arbitrary code on affected devices. Although authentication is needed to exploit this vulnerability, the current authentication mechanism can be bypassed. The flaw is due to the improper validation of a user-supplied string within the rc_service parameter in apply_bind.cgi, allowing attackers to execute commands in the context of root. This issue poses a significant risk to the security of network environments where the router is deployed.
Affected Version(s)
R7800 firmware version 1.0.2.76
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ho\xc3\xa0ng Th\xe1\xba\xa1ch Nguy\xe1\xbb\x85n, Lucas Tay