CVE-2020-10924
published 2020-07-28CVE-2020-10924: This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Although…
PriorityP278high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EXPLOIT
EPSS
87.34%
99.7th percentile
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9643.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | r6700 | — | — |
| netgear | r6700_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for SOAPAction UPnP messages originating from network-adjacent (LAN) hosts directed at TCP port 5000 on NETGEAR R6700 devices, which is the attack vector for both the auth bypass (CVE-2020-10923) and the buffer overflow (CVE-2020-10924). ↗
- →Alert on unexpected telnet enablement (TCP/23 open) on NETGEAR R6700 routers following UPnP traffic to port 5000, as successful exploitation enables a telnet server on port 23/tcp. ↗
- →Detect upnpd process crash on NETGEAR R6700 routers; successful exploitation causes the upnpd binary to crash and it will not restart until reboot, which can serve as a post-exploitation indicator. ↗
- →Flag admin password resets to the factory default ('password') on NETGEAR R6700v3 devices, as the exploit resets the admin credential to its factory default as part of the attack chain. ↗
- ·Exploitation is limited to network-adjacent (LAN-side) attackers only; the UPnP service on TCP/5000 is not exposed to the WAN by default. ↗
- ·The exploit can only be triggered once per router reboot because the upnpd binary crashes and does not restart automatically. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
2020-07-28
Published