Arbitrary Code Execution Vulnerability in NETGEAR Nighthawk Router
CVE-2021-27253
What is CVE-2021-27253?
A vulnerability exists in the NETGEAR Nighthawk R7800 that enables network-adjacent attackers to execute arbitrary code on affected devices. Although authentication is needed to exploit this vulnerability, the current authentication mechanism can be bypassed. The flaw is due to the improper validation of a user-supplied string within the rc_service parameter in apply_bind.cgi, allowing attackers to execute commands in the context of root. This issue poses a significant risk to the security of network environments where the router is deployed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
R7800 firmware version 1.0.2.76
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved