Unknown
CVE-2021-27255
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)CVE-2021-27255
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the refresh_status.aspx endpoint. The issue results from a lack of authentication required to start a service on the server. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12360.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- br200 firmware,
- br500 firmware,
- d7800 firmware,
- ex6100v2 firmware,
- ex6150v2 firmware,
- ex6250 firmware,
- ex6400 firmware,
- ex6400v2 firmware,
- ex6410 firmware,
- ex6420 firmware,
- ex7300 firmware,
- ex7300v2 firmware,
- ex7320 firmware,
- ex7700 firmware,
- ex8000 firmware,
- lbr20 firmware,
- r7800 firmware,
- r8900 firmware,
- r9000 firmware,
- rbk12 firmware,
- rbk13 firmware,
- rbk14 firmware,
- rbk15 firmware,
- rbk20 firmware,
- rbk23 firmware,
- rbk40 firmware,
- rbk43 firmware,
- rbk43s firmware,
- rbk44 firmware,
- rbk50 firmware,
- rbk53 firmware,
- rbr10 firmware,
- rbr20 firmware,
- rbr40 firmware,
- rbr50 firmware,
- rbs10 firmware,
- rbs20 firmware,
- rbs40 firmware,
- rbs50 firmware,
- rbs50y firmware,
- xr450 firmware,
- xr500 firmware,
- xr700 firmware
Weaknesses
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: