CVE-2021-27255

Severity
8.8HIGH
EPSS
1.7%
top 17.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 24

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the refresh_status.aspx endpoint. The issue results from a lack of authentication required to start a service on the server. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12360.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages44 packages

NVDnetgear/r7800_firmware< 1.0.2.80
NVDnetgear/br200_firmware< 5.10.0.5
NVDnetgear/br500_firmware< 5.10.0.5
NVDnetgear/d7800_firmware< 1.0.1.60
NVDnetgear/lbr20_firmware< 2.6.3.50

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h584-8p47-255w: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 12022-05-24
CVEList
CVE-2021-27255: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 12021-03-05
CVE-2021-27255 (HIGH CVSS 8.8) | This vulnerability allows remote at | cvebase.io