← Back

CVE-2021-34865

nvd nist
Published: Jan 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13313.

Affected (17)

17 products
Ac2100 Firmware
Ac2400 Firmware
Ac2600 Firmware
D7000v1 Firmware
R6220 Firmware
R6230 Firmware
R6260 Firmware
R6330 Firmware
R6350 Firmware
R6700v2 Firmware
R6800 Firmware
R6850 Firmware
R6900v2 Firmware
R7200 Firmware
R7350 Firmware
R7400 Firmware
R7450 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
Ac2100
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
Ac2400
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
Ac2600
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.1.80
Running on/withPlatform Versions
Netgear
D7000v1
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0.110
Running on/withPlatform Versions
Netgear
R6220
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0.110
Running on/withPlatform Versions
Netgear
R6230
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0.84
Running on/withPlatform Versions
Netgear
R6260
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0.84
Running on/withPlatform Versions
Netgear
R6330
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0.84
Running on/withPlatform Versions
Netgear
R6350
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R6700v2
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R6800
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.1.0.84
Running on/withPlatform Versions
Netgear
R6850
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R6900v2
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R7200
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R7350
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R7400
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.2.0.88
Running on/withPlatform Versions
Netgear
R7450
All versions

References (4)

Timeline

No history available yet.