Remote File Deletion in NETGEAR ProSAFE Network Management System
CVE-2021-27272
Key Information:
- Vendor
Netgear
- Vendor
- CVE Published:
- 29 March 2021
What is CVE-2021-27272?
This vulnerability enables remote attackers to delete arbitrary files on installations of the NETGEAR ProSAFE Network Management System version 1.6.0.26. Although the attack requires authentication, the authentication mechanism can be circumvented. The flaw lies in the processing of the path parameter within the ReportTemplateController class, where user-supplied input is not sufficiently validated before being utilized in file operations. An attacker can exploit this issue to induce a denial-of-service condition on the system, potentially disrupting service availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ProSAFE Network Management System 1.6.0.26
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved