CVE-2021-20167
published 2021-12-30CVE-2021-20167: Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name…
PriorityP278high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
8.53%
94.4th percentile
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rax43_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring POST requests to /cgi-bin/readycloud_control.cgi with an oversized query string (>200 chars of repeated characters) followed by /api/users, indicative of the buffer overrun authentication bypass chained with command injection. ↗
- →Detect command injection payload in the 'name' parameter of the POST body: look for shell metacharacters such as single-quotes and $() subshell syntax (e.g., ';$(...)') targeting readycloud_control.cgi. ↗
- →Alert on outbound curl/HTTP requests originating from the router process (readycloud_control.cgi) as a sign of successful command injection; interactsh-style OOB callback detection via User-Agent 'curl' is used in PoC validation. ↗
- →This vulnerability chains CVE-2021-20166 (buffer overrun in URL parsing of cgi-bin endpoint for authentication bypass) with CVE-2021-20167 (command injection in 'name' parameter); detections should cover both the oversized URL path and the injected name field together. ↗
- ·The buffer overrun authentication bypass (CVE-2021-20166) is required to exploit the command injection (CVE-2021-20167) without prior authentication; the oversized query string in the URL is the bypass mechanism, not a standalone indicator. ↗
- ·Affected firmware is specifically Netgear RAX43 version 1.0.3.96; detections and mitigations should be scoped to this firmware version (CPE: cpe:2.3:o:netgear:rax43_firmware:1.0.3.96). ↗
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.7HIGHAV:A/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8r96-wwm9-5vjv: Netgear RAX43 version 1
ghsa_unreviewed·2021-12-31
CVE-2021-20167 [HIGH] CWE-77 GHSA-8r96-wwm9-5vjv: Netgear RAX43 version 1
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
VulnCheck
NETGEAR rax43 Improper Neutralization of Special Elements used in a Command ('Command Injection')
vulncheck·2021·CVSS 8.0
CVE-2021-20167 [HIGH] NETGEAR rax43 Improper Neutralization of Special Elements used in a Command ('Command Injection')
NETGEAR rax43 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
Affected: NETGEAR rax43
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/; https://www.f5.com/labs/articles/threat-intelligence/sensor-intel-series-top-cves-august-2024; https://www.f5.com/labs/articles/threat-intelligence/botpoke-scanner-switches-ip; https://www.f5.com/labs/articles/threat-intelligence/continued-scanning-fo
No detection rules found.
Nuclei
Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
nuclei·CVSS 8.8
CVE-2021-20167 [HIGH] Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Netgear RAX43 version 1.0.3.96 contains a command injection and authentication bypass vulnerability. The readycloud_control.cgi CGI application is vulnerable to command injection in the name parameter. Additionally, the URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the application. Note: This vulnerability uses a combination of CVE-2021-20166 and CVE-2021-20167.
Template:
id: CVE-2021-20167
info:
name: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
author: gy741
severity: high
description: 'Netgear RAX43 version 1.0.3.96 contains a command injection and authentication bypass vulnerabilit
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19·CVSS 8.8
CVE-2021-20166 [HIGH] Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Yue Guan
Published: August 19, 2022
Trend Reports
Vulnerabilities
Attack analysis
CVE-2021-20166
CVE-2021-20167
CVE-2021-21881
CVE-2021-24762
CVE-2021-28169
CVE-2021-31589
CVE-2021-39226
CVE-2021-4045
CVE-2021-43711
CVE-2022-21371
CVE-2022-21662
CVE-2022-22536
CVE-2022-22947
CVE-2022-22954
CVE-2022-22963
CVE-2022-22965
CVE-2022-24112
CVE-2022-24260
CVE-2022-25060
CVE-2022-25075
CVE-2022-25134
CVE-2022-27226
CVE-2022-29464
Exploit in the wild
Network security trends
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
Other insights that could assist defenders includ
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2021-12-30
Published
Exploited in the wild