CVE-2021-27239
published 2021-03-29CVE-2021-27239: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98…
PriorityP356high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.75%
50.6th percentile
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the upnpd service, which listens on UDP port 1900 by default. A crafted MX header field in an SSDP message can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11851.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | d6220_firmware | < 1.0.0.68 | 1.0.0.68 |
| netgear | d6400_firmware | < 1.0.0.102 | 1.0.0.102 |
| netgear | d7000_firmware | < 1.0.0.66 | 1.0.0.66 |
| netgear | d8500_firmware | < 1.0.3.60 | 1.0.3.60 |
| netgear | dc112a_firmware | < 1.0.0.54 | 1.0.0.54 |
| netgear | ex7000_firmware | < 1.0.1.94 | 1.0.1.94 |
| netgear | ex7500_firmware | < 1.0.0.72 | 1.0.0.72 |
| netgear | multiple_routers | — | — |
| netgear | r6250_firmware | < 1.0.4.48 | 1.0.4.48 |
| netgear | r6300_firmware | < 1.0.4.50 | 1.0.4.50 |
| netgear | r6400_firmware | < 1.0.1.68 | 1.0.1.68 |
| netgear | r6400_firmware | < 1.0.4.102 | 1.0.4.102 |
| netgear | r6700_firmware | < 1.0.4.102 | 1.0.4.102 |
| netgear | r6900p_firmware | < 1.3.2.132 | 1.3.2.132 |
| netgear | r7000_firmware | < 1.0.11.116 | 1.0.11.116 |
| netgear | r7000p_firmware | < 1.3.2.132 | 1.3.2.132 |
| netgear | r7100lg_firmware | < 1.0.0.64 | 1.0.0.64 |
| netgear | r7850_firmware | < 1.0.5.68 | 1.0.5.68 |
| netgear | r7900_firmware | < 1.0.4.38 | 1.0.4.38 |
| netgear | r7900p_firmware | < 1.4.1.68 | 1.4.1.68 |
| netgear | r7960p_firmware | < 1.4.1.68 | 1.4.1.68 |
| netgear | r8000_firmware | < 1.0.4.68 | 1.0.4.68 |
| netgear | r8000p_firmware | < 1.4.1.68 | 1.4.1.68 |
| netgear | r8300_firmware | < 1.0.2.144 | 1.0.2.144 |
| netgear | r8500_firmware | < 1.0.2.144 | 1.0.2.144 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cifs-utils vulnerabilities
osv·2025-08-07·CVSS 7.0
CVE-2020-14342 cifs-utils vulnerabilities
cifs-utils vulnerabilities
Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a
password. In certain environments, a local attacker could possibly use this
issue to escalate privileges. (CVE-2020-14342)
It was discovered that cifs-utils incorrectly used host credentials when
mounting a krb5 CIFS file system from within a container. An attacker
inside a container could possibly use this issue to obtain access to
sensitive information. (CVE-2021-20208)
It was discovered that cifs-utils incorrectly handled certain command-line
arguments. A local attacker could possibly use this issue to obtain root
privileges. (CVE-2022-27239)
It was discovered that cifs-utils incorrectly handled verbose logging. A
local attacker could possibly use this issue to obtain sensitive
inf
OSV
cifs-utils vulnerabilities
osv·2022-06-02·CVSS 7.0
CVE-2020-14342 cifs-utils vulnerabilities
cifs-utils vulnerabilities
Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a
password. In certain environments, a local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-14342)
It was discovered that cifs-utils incorrectly used host credentials when
mounting a krb5 CIFS file system from within a container. An attacker
inside a container could possibly use this issue to obtain access to
sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu
20.04 LTS. (CVE-2021-20208)
It was discovered that cifs-utils incorrectly handled certain command-line
arguments. A local attacker could possibly use this issue to obtain root
privileges. (CVE-2022-27239)
It was discov
GHSA
GHSA-hqww-3wrx-q5gv: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1
ghsa_unreviewed·2022-05-24
CVE-2021-27239 [HIGH] CWE-121 GHSA-hqww-3wrx-q5gv: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the upnpd service, which listens on UDP port 1900 by default. A crafted MX header field in an SSDP message can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11851.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000062820/Security-Advisory-for-Stack-based-Buffer-Overflow-Remote-Code-Execution-Vulnerability-on-Some-Routers-PSV-2020-0432https://www.zerodayinitiative.com/advisories/ZDI-21-206/https://kb.netgear.com/000062820/Security-Advisory-for-Stack-based-Buffer-Overflow-Remote-Code-Execution-Vulnerability-on-Some-Routers-PSV-2020-0432https://www.zerodayinitiative.com/advisories/ZDI-21-206/
2021-03-29
Published