Remote Code Execution Vulnerability in NETGEAR R7800 Firmware
CVE-2021-27255
6.3MEDIUM
Summary
A vulnerability in the NETGEAR R7800 firmware allows attackers to execute arbitrary code remotely without authentication. The flaw is located in the refresh_status.aspx endpoint, where insufficient authentication mechanisms permit unauthorized service initiation on the server. This situation can lead to an attacker executing code with root privileges, potentially compromising the entire system. This vulnerability raises serious security concerns for users of the affected firmware version.
Affected Version(s)
R7800 firmware version 1.0.2.76
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
STARLabs