Remote Code Execution Flaw in NETGEAR ProSAFE Network Management System
CVE-2021-27273
Key Information:
- Vendor
Netgear
- Vendor
- CVE Published:
- 29 March 2021
What is CVE-2021-27273?
The NETGEAR ProSAFE Network Management System version 1.6.0.26 has a security vulnerability that allows remote attackers to execute arbitrary code. Although authentication is required, the existing authentication mechanism can be bypassed. The issue originates from improper validation of the 'fileName' parameter within the SettingConfigController class, allowing unauthorized code execution in the context of SYSTEM. This vulnerability poses a significant risk to users of the affected product and requires immediate attention.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ProSAFE Network Management System 1.6.0.26
References
EPSS Score
79% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved