CVE-2021-41314Injection in Netgear Gc108p Firmware

Severity
8.8HIGHNVD
EPSS
4.9%
top 10.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 24

Description

Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2" string). This leads to admin session crafting and therefore gaining full web UI admin privileges by an unauthenticated attacker. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages20 packages

🔴Vulnerability Details

2
GHSA
GHSA-g292-cmh3-q4c9: Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authenticat2022-05-24
CVEList
CVE-2021-41314: Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authenticat2021-09-16

🔍Detection Rules

1
Suricata
ET EXPLOIT Netgear Seventh Inferno CVE-2021-41314 (new line injection)2021-09-16
CVE-2021-41314 — Injection in Netgear Gc108p Firmware | cvebase