This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11076.
2021-02-12T00:15:12.500
2024-11-21T05:21:57.107
Modified
CVSSv3.1: 8.8 (HIGH)
AV:A/AC:L/Au:N/C:C/I:C/A:C
6.5
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | cbk40_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | cbk40 | - | No |
Operating System | netgear | cbk43_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | cbk43 | - | No |
Operating System | netgear | cbr40_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | cbr40 | - | No |
Operating System | netgear | ex6200_firmware | < 1.0.1.82 | Yes |
Hardware | netgear | ex6200 | v2 | No |
Operating System | netgear | ex7700_firmware | < 1.0.0.210 | Yes |
Hardware | netgear | ex7700 | - | No |
Operating System | netgear | ex8000_firmware | < 1.0.1.224 | Yes |
Hardware | netgear | ex8000 | - | No |
Operating System | netgear | rbk12_firmware | < 2.6.1.44 | Yes |
Hardware | netgear | rbk12 | - | No |
Operating System | netgear | rbk13_firmware | < 2.6.1.44 | Yes |
Hardware | netgear | rbk13 | - | No |
Operating System | netgear | rbk14_firmware | < 2.6.1.44 | Yes |
Hardware | netgear | rbk14 | - | No |
Operating System | netgear | rbk15_firmware | < 2.6.1.44 | Yes |
Hardware | netgear | rbk15 | - | No |
Operating System | netgear | rbr10_firmware | < 2.6.1.44 | Yes |
Hardware | netgear | rbr10 | - | No |
Operating System | netgear | rbs10_firmware | < 2.6.1.44 | Yes |
Hardware | netgear | rbs10 | - | No |
Operating System | netgear | rbk20w_firmware | < 2.6.1.36 | Yes |
Hardware | netgear | rbk20w | - | No |
Operating System | netgear | rbk23w_firmware | < 2.6.1.36 | Yes |
Hardware | netgear | rbk23w | - | No |
Operating System | netgear | rbk20_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk20_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk20 | - | No |
Operating System | netgear | rbk22_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk22_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk22 | - | No |
Operating System | netgear | rbk23_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk23_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk23 | - | No |
Operating System | netgear | rbr20_firmware | < 2.6.1.36 | Yes |
Hardware | netgear | rbr20 | - | No |
Operating System | netgear | rbs20_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbs20 | - | No |
Operating System | netgear | rbk30_firmware | < 2.6.1.36 | Yes |
Hardware | netgear | rbk30 | - | No |
Operating System | netgear | rbk33_firmware | < 2.6.1.36 | Yes |
Hardware | netgear | rbk33 | - | No |
Operating System | netgear | rbk40_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk40_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk40 | - | No |
Operating System | netgear | rbk43_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk43_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk43 | - | No |
Operating System | netgear | rbk43s_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk43s_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk43s | - | No |
Operating System | netgear | rbk44_router_firmware | < 2.6.1.36 | Yes |
Operating System | netgear | rbk44_satellite_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbk44 | - | No |
Operating System | netgear | rbr40_firmware | < 2.6.1.36 | Yes |
Hardware | netgear | rbr40 | - | No |
Operating System | netgear | rbs40_firmware | < 2.6.1.38 | Yes |
Hardware | netgear | rbs40 | - | No |
Operating System | netgear | rbk50_firmware | < 2.6.1.40 | Yes |
Hardware | netgear | rbk50 | - | No |
Operating System | netgear | rbk50v_firmware | < 2.6.1.40 | Yes |
Hardware | netgear | rbk50v | - | No |
Operating System | netgear | rbk52w_firmware | < 2.6.1.40 | Yes |
Hardware | netgear | rbk52w | - | No |
Operating System | netgear | rbr50_firmware | < 2.6.1.40 | Yes |
Hardware | netgear | rbr50 | - | No |
Operating System | netgear | rbs50_firmware | < 2.6.1.40 | Yes |
Hardware | netgear | rbs50 | - | No |