← Back

CVE-2021-27239

nvd nist
Published: Mar 29, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the upnpd service, which listens on UDP port 1900 by default. A crafted MX header field in an SSDP message can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11851.

Affected (36)

35 products
D6220 Firmware
D6400 Firmware
D7000 Firmware
D8500 Firmware
Dc112a Firmware
Ex7000 Firmware
Ex7500 Firmware
R6250 Firmware
R6300 Firmware
R6400 Firmware
R6700 Firmware
R6900p Firmware
R7000 Firmware
R7000p Firmware
R7100lg Firmware
R7850 Firmware
R7900 Firmware
R7900p Firmware
R7960p Firmware
R8000 Firmware
R8000p Firmware
R8300 Firmware
R8500 Firmware
Rax200 Firmware
Rax75 Firmware
Rax80 Firmware
Rbr750 Firmware
Rbr850 Firmware
Rbs40v Firmware
Rbs750 Firmware
Rbs850 Firmware
Rs400 Firmware
Wndr3400 Firmware
Wnr3500l Firmware
Xr300 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.0.68
Running on/withPlatform Versions
Netgear
D6220
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.0.102
Running on/withPlatform Versions
Netgear
D6400
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.0.66
Running on/withPlatform Versions
Netgear
D7000
Version v2
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.3.60
Running on/withPlatform Versions
Netgear
D8500
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.0.54
Running on/withPlatform Versions
Netgear
Dc112a
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.1.94
Running on/withPlatform Versions
Netgear
Ex7000
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.0.72
Running on/withPlatform Versions
Netgear
Ex7500
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4.48
Running on/withPlatform Versions
Netgear
R6250
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4.50
Running on/withPlatform Versions
Netgear
R6300
Version v2
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.1.68
Running on/withPlatform Versions
Netgear
R6400
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4.102
Running on/withPlatform Versions
Netgear
R6400
Version v2
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4.102
Running on/withPlatform Versions
Netgear
R6700
Version v3
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.2.132
Running on/withPlatform Versions
Netgear
R6900p
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.11.116
Running on/withPlatform Versions
Netgear
R7000
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.3.2.132
Running on/withPlatform Versions
Netgear
R7000p
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.0.64
Running on/withPlatform Versions
Netgear
R7100lg
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.5.68
Running on/withPlatform Versions
Netgear
R7850
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4.38
Running on/withPlatform Versions
Netgear
R7900
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.1.68
Running on/withPlatform Versions
Netgear
R7900p
All versions
Configuration T
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.1.68
Running on/withPlatform Versions
Netgear
R7960p
All versions
Configuration U
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4.68
Running on/withPlatform Versions
Netgear
R8000
All versions
Configuration V
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.1.68
Running on/withPlatform Versions
Netgear
R8000p
All versions
Configuration W
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.2.144
Running on/withPlatform Versions
Netgear
R8300
All versions
Configuration X
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.2.144
Running on/withPlatform Versions
Netgear
R8500
All versions
Configuration Y
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.2.88
Running on/withPlatform Versions
Netgear
Rax200
All versions
Configuration Z
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.3.102
Running on/withPlatform Versions
Netgear
Rax75
All versions
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.3.102
Running on/withPlatform Versions
Netgear
Rax80
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.2.17.12
Running on/withPlatform Versions
Netgear
Rbr750
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.2.17.12
Running on/withPlatform Versions
Netgear
Rbr850
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.6.2.4
Running on/withPlatform Versions
Netgear
Rbs40v
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.2.17.12
Running on/withPlatform Versions
Netgear
Rbs750
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.2.17.12
Running on/withPlatform Versions
Netgear
Rbs850
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.5.0.68
Running on/withPlatform Versions
Netgear
Rs400
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.1.38
Running on/withPlatform Versions
Netgear
Wndr3400
Version v3
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.66
Running on/withPlatform Versions
Netgear
Wnr3500l
Version v2
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.3.56
Running on/withPlatform Versions
Netgear
Xr300
All versions

Timeline

No history available yet.