CVE-2022-27645
published 2023-03-29CVE-2022-27645: This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not…
high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15762.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | lax20_firmware | < 1.1.6.34 | 1.1.6.34 |
| netgear | r6400_firmware | < 1.0.4.126 | 1.0.4.126 |
| netgear | r6700_firmware | < 1.0.4.126 | 1.0.4.126 |
| netgear | r6700v3 | — | — |
| netgear | r7000_firmware | < 1.0.11.134 | 1.0.11.134 |
| netgear | r7850_firmware | < 1.0.5.84 | 1.0.5.84 |
| netgear | r7900p_firmware | < 1.4.3.88 | 1.4.3.88 |
| netgear | r7960p_firmware | < 1.4.3.88 | 1.4.3.88 |
| netgear | r8000_firmware | < 1.0.4.84 | 1.0.4.84 |
| netgear | r8000p_firmware | < 1.4.3.88 | 1.4.3.88 |
| netgear | r8500_firmware | < 1.0.2.158 | 1.0.2.158 |
| netgear | rax15_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax200_firmware | < 1.0.6.138 | 1.0.6.138 |
| netgear | rax20_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax35_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax38_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax40_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax42_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax43_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax45_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax48_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax50_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax50s_firmware | < 1.0.10.110 | 1.0.10.110 |
| netgear | rax75_firmware | < 1.0.6.138 | 1.0.6.138 |