8.8
CVE-2021-34947
- EPSS 0.39%
- Published 07.05.2024 23:15:07
- Last modified 14.08.2025 01:42:44
- Source zdi-disclosures@trendmicro.com
- Teams watchlist Login
- Open Login
NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of the soap_block_table file. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-13055.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Netgear ≫ D7800 Firmware Version < 1.0.1.64
Netgear ≫ Ex2700 Firmware Version < 1.0.1.66
Netgear ≫ Ex6100 Firmware Version < 1.0.1.106
Netgear ≫ Ex6150 Firmware Version < 1.0.1.106
Netgear ≫ Ex6200 Firmware Version < 1.0.1.86
Netgear ≫ Ex6250 Firmware Version < 1.0.0.146
Netgear ≫ Ex6400 Firmware Version < 1.0.2.164
Netgear ≫ Ex6400v2 Firmware Version < 1.0.0.146
Netgear ≫ Ex6410 Firmware Version < 1.0.0.146
Netgear ≫ Ex6420 Firmware Version < 1.0.0.146
Netgear ≫ Ex6500v1 Firmware Version < 1.0.0.146
Netgear ≫ Ex7300 Firmware Version < 1.0.2.164
Netgear ≫ Ex7300v2 Firmware Version < 1.0.0.146
Netgear ≫ Ex7320 Firmware Version < 1.0.0.146
Netgear ≫ Ex7700 Firmware Version < 1.0.0.222
Netgear ≫ Ex8000 Firmware Version < 1.0.1.238
Netgear ≫ Lbr1020 Firmware Version < 2.6.5.32
Netgear ≫ Lbr20 Firmware Version < 2.6.5.32
Netgear ≫ R6700ax Firmware Version < 1.0.5.108
Netgear ≫ R7800 Firmware Version < 1.0.2.84
Netgear ≫ R8900 Firmware Version < 1.0.5.36
Netgear ≫ R9000 Firmware Version < 1.0.5.36
Netgear ≫ Rax10 Firmware Version < 1.0.5.108
Netgear ≫ Rax120 Firmware Version < 1.2.2.24
Netgear ≫ Rax120v2 Firmware Version < 1.2.2.24
Netgear ≫ Rax70 Firmware Version < 1.0.5.108
Netgear ≫ Rax78 Firmware Version < 1.0.5.108
Netgear ≫ Rbr10 Firmware Version < 2.7.4.24
Netgear ≫ Rbr20 Firmware Version < 2.7.4.24
Netgear ≫ Rbr40 Firmware Version < 2.7.4.24
Netgear ≫ Rbr50 Firmware Version < 2.7.4.24
Netgear ≫ Rbs10 Firmware Version < 2.7.4.24
Netgear ≫ Rbs20 Firmware Version < 2.7.4.24
Netgear ≫ Rbs40 Firmware Version < 2.7.4.24
Netgear ≫ Rbs50 Firmware Version < 2.7.4.24
Netgear ≫ Rbs50y Firmware Version < 2.7.4.12
Netgear ≫ Wn3000rpv2 Firmware Version < 1.0.0.88
Netgear ≫ Wnr2000v5 Firmware Version < 1.0.0.78
Netgear ≫ Xr450 Firmware Version < 2.3.2.130
Netgear ≫ Xr500 Firmware Version < 2.3.2.130
Netgear ≫ Xr700 Firmware Version < 1.0.1.44
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.39% | 0.592 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
zdi-disclosures@trendmicro.com | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.