CVE-2021-34980
Severity
8.8HIGH
EPSS
0.2%
top 54.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateJan 14
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setupwizard.cgi page. When parsing the SOAP_LOGIN_TOKEN environment variable, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to e…
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-65c2-8xvq-gj7j: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1↗2022-01-14
CVEList▶
CVE-2021-34980: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1↗2022-01-13