cbcvebase.
CVE-2021-45511
published 2021-12-26

CVE-2021-45511: Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000…

PriorityP182critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
17.64%
96.8th percentile
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000 before 2021-08-27, R6220 before 2021-08-27, R6230 before 2021-08-27, R6260 before 2021-08-27, R6330 before 2021-08-27, R6350 before 2021-08-27, R6700v2 before 2021-08-27, R6800 before 2021-08-27, R6850 before 2021-08-27, R6900v2 before 2021-08-27, R7200 before 2021-08-27, R7350 before 2021-08-27, R7400 before 2021-08-27, and R7450 before 2021-08-27.

Affected

17 ranges
VendorProductVersion rangeFixed in
netgearac2100_firmware< 1.2.0.881.2.0.88
netgearac2400_firmware< 1.2.0.881.2.0.88
netgearac2600_firmware< 1.2.0.881.2.0.88
netgeard7000_firmware< 1.0.1.801.0.1.80
netgearr6220_firmware< 1.1.0.1101.1.0.110
netgearr6230_firmware< 1.1.0.1101.1.0.110
netgearr6260_firmware< 1.1.0.841.1.0.84
netgearr6330_firmware< 1.1.0.841.1.0.84
netgearr6350_firmware< 1.1.0.841.1.0.84
netgearr6700v2_firmware< 1.2.0.881.2.0.88
netgearr6800_firmware< 1.2.0.881.2.0.88
netgearr6850_firmware< 1.1.0.841.1.0.84
netgearr6900v2_firmware< 1.2.0.881.2.0.88
netgearr7200_firmware< 1.2.0.881.2.0.88
netgearr7350_firmware< 1.2.0.881.2.0.88
netgearr7400_firmware< 1.2.0.881.2.0.88
netgearr7450_firmware< 1.2.0.881.2.0.88

Detection & IOCsextracted from sources · hover to see the quote

urlauxiliary/admin/http/netgear_pnpx_getsharefolderlist_auth_bypass
processmini_http
commandPNPX_GetShareFolderList
  • Monitor for unauthenticated HTTP requests invoking PNPX_GetShareFolderList on NETGEAR router admin interfaces, which can expose the admin password in plaintext without authentication.
  • After exploitation, the attacker enables telnet on the target router and logs in as 'root' — alert on unexpected telnet service activation or new telnet sessions on affected NETGEAR devices.
  • Use the Metasploit auxiliary module auxiliary/scanner/telnet/telnet_login as a post-exploitation indicator — detect its characteristic telnet login attempts following suspicious HTTP activity against the router.
  • ·Affected firmware versions are prior to 1.2.0.88, 1.0.1.80, 1.1.0.110, and 1.1.0.84 across the listed NETGEAR device models. Devices patched on or after 2021-08-27 are not vulnerable.
  • ·A wide range of NETGEAR devices are affected: AC2100, AC2400, AC2600, D7000, R6220, R6230, R6260, R6330, R6350, R6700v2, R6800, R6850, R6900v2, R7200, R7350, R7400, and R7450 — all before 2021-08-27.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.