← Back

CVE-2021-40847

nvd nist
Published: Sep 21, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR to obtain version information and updates to the circled daemon and its filtering database. However, database updates from NETGEAR are unsigned and downloaded via cleartext HTTP. As such, an attacker with the ability to perform a MitM attack on the device can respond to circled update requests with a crafted, compressed database file, the extraction of which gives the attacker the ability to overwrite executable files with attacker-controlled code. This affects R6400v2 1.0.4.106, R6700 1.0.2.16, R6700v3 1.0.4.106, R6900 1.0.2.16, R6900P 1.3.2.134, R7000 1.0.11.123, R7000P 1.3.2.134, R7850 1.0.5.68, R7900 1.0.4.38, R8000 1.0.4.68, and RS400 1.5.0.68.

Affected (11)

11 products
R6400v2 Firmware
R6700 Firmware
R6700v3 Firmware
R6900 Firmware
R6900p Firmware
R7000 Firmware
R7000p Firmware
R7850 Firmware
R7900 Firmware
R8000 Firmware
Rs400 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.106
Running on/withPlatform Versions
Netgear
R6400v2
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2.16
Running on/withPlatform Versions
Netgear
R6700
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.106
Running on/withPlatform Versions
Netgear
R6700v3
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2.16
Running on/withPlatform Versions
Netgear
R6900
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.2.134
Running on/withPlatform Versions
Netgear
R6900p
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.11.123
Running on/withPlatform Versions
Netgear
R7000
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.2.134
Running on/withPlatform Versions
Netgear
R7000p
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.5.68
Running on/withPlatform Versions
Netgear
R7850
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.38
Running on/withPlatform Versions
Netgear
R7900
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.68
Running on/withPlatform Versions
Netgear
R8000
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.5.0.68
Running on/withPlatform Versions
Netgear
Rs400
All versions

Timeline

No history available yet.