cbcvebase.
CVE-2020-10923
published 2020-07-28

CVE-2020-10923: This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers…

PriorityP278high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EXPLOIT
EPSS
84.68%
99.7th percentile
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000. A crafted UPnP message can be used to bypass authentication. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-9642.

Affected

2 ranges
VendorProductVersion rangeFixed in
netgearr6700
netgearr6700_firmware

Detection & IOCsextracted from sources · hover to see the quote

portTCP/5000
portUDP/23
portTCP/23
process/usr/sbin/upnpd
commandSOAPAction UPnP messages
  • Monitor for SOAPAction UPnP messages sent to TCP port 5000 on NETGEAR R6700 devices from network-adjacent (LAN) hosts — this is the authentication bypass vector for CVE-2020-10923.
  • Alert on unexpected crash/absence of the /usr/sbin/upnpd process on NETGEAR R6700v3 routers, as successful exploitation causes the upnpd binary to crash and not restart until reboot.
  • Detect unexpected telnet service activation on TCP/23 of NETGEAR R6700v3 routers following UPnP traffic to TCP/5000 — this indicates post-exploitation via telnetenable.
  • Flag use of the Metasploit module auxiliary/admin/http/netgear_r6700_pass_reset or exploit/linux/telnet/netgear_telnetenable in network or endpoint telemetry as direct indicators of exploitation attempts.
  • ·Exploitation is limited to network-adjacent (LAN) attackers only — this vulnerability is not remotely exploitable from the internet.
  • ·The Metasploit module currently only supports firmware versions V1.0.0.4.82_10.0.57 and V1.0.0.4.84_10.0.58; other firmware versions in the vulnerable range (up to but not including V1.0.4.94) may require additional development.
  • ·Exploitation can only occur once per router reboot, as the upnpd binary crashes and does not restart automatically — repeated exploitation attempts will fail until the device is rebooted.
  • ·CVE-2020-10923 (auth bypass) is chained with CVE-2020-10924 (buffer overflow in upnpd) to achieve full admin password reset; neither vulnerability alone achieves code execution.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.