cbcvebase.
CVE-2022-27646
published 2023-03-29

CVE-2022-27646: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although…

high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled daemon. A crafted circleinfo.txt file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15879.

Affected

25 ranges
VendorProductVersion rangeFixed in
netgearcbr40_firmware< 2.5.0.282.5.0.28
netgearlbr1020_firmware< 2.7.4.22.7.4.2
netgearlbr20_firmware< 2.7.4.22.7.4.2
netgearr6400_firmware< 1.0.4.1261.0.4.126
netgearr6700_firmware< 1.0.4.1261.0.4.126
netgearr6700v3
netgearr6900p_firmware< 1.3.3.1481.3.3.148
netgearr7000_firmware< 1.0.11.1341.0.11.134
netgearr7000p_firmware< 1.3.3.1481.3.3.148
netgearr7850_firmware< 1.0.5.841.0.5.84
netgearr7960p_firmware< 1.4.3.881.4.3.88
netgearr8000_firmware< 1.0.4.841.0.4.84
netgearr8000p_firmware< 1.4.3.881.4.3.88
netgearrax200_firmware< 1.0.6.1381.0.6.138
netgearrax75_firmware< 1.0.6.1381.0.6.138
netgearrax80_firmware< 1.0.6.1381.0.6.138
netgearrbr10_firmware< 2.7.4.242.7.4.24
netgearrbr20_firmware< 2.7.4.242.7.4.24
netgearrbr40_firmware< 2.7.4.242.7.4.24
netgearrbr50_firmware< 2.7.4.242.7.4.24
netgearrbs10_firmware< 2.7.4.242.7.4.24
netgearrbs20_firmware< 2.7.4.242.7.4.24
netgearrbs40_firmware< 2.7.4.242.7.4.24
netgearrbs50_firmware< 2.7.4.242.7.4.24
netgearrs400_firmware< 1.5.1.861.5.1.86