ID

VAR-202203-2054


TITLE

(Pwn2Own) NETGEAR R6700v3 Missing Authentication for Critical Function Arbitrary File Upload Vulnerability

Trust: 0.7

sources: ZDI: ZDI-22-521

DESCRIPTION

This vulnerability allows network-adjacent attackers to upload arbitrary files on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability.The specific flaw exists within the Circle Parental Control feature, which listens on TCP ports 4444 and 4567 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.

Trust: 0.7

sources: ZDI: ZDI-22-521

AFFECTED PRODUCTS

vendor:netgearmodel:r6700v3scope: - version: -

Trust: 0.7

sources: ZDI: ZDI-22-521

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: ZDI-22-521
value: LOW

Trust: 0.7

ZDI: ZDI-22-521
baseSeverity: LOW
baseScore: 3.1
vectorString: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.6
impactScore: 1.4
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-22-521

PATCH

title:NETGEAR has issued an update to correct this vulnerability.url:https://kb.netgear.com/000064724/security-advisory-for-security-misconfiguration-on-some-routers-and-orbi-wifi-systems-psv-2021-0330

Trust: 0.7

sources: ZDI: ZDI-22-521

EXTERNAL IDS

db:ZDI_CANid:ZDI-CAN-15782

Trust: 0.7

db:ZDIid:ZDI-22-521

Trust: 0.7

sources: ZDI: ZDI-22-521

REFERENCES

url:https://kb.netgear.com/000064724/security-advisory-for-security-misconfiguration-on-some-routers-and-orbi-wifi-systems-psv-2021-0330

Trust: 0.7

sources: ZDI: ZDI-22-521

CREDITS

Flashback Team: Pedro Ribeiro (@pedrib1337) && Radek Domanski (@RabbitPro)

Trust: 0.7

sources: ZDI: ZDI-22-521

SOURCES

db:ZDIid:ZDI-22-521

LAST UPDATE DATE

2022-05-17T01:43:01.245000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-22-521date:2022-03-23T00:00:00

SOURCES RELEASE DATE

db:ZDIid:ZDI-22-521date:2022-03-23T00:00:00