This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-12287.
2021-03-05T20:15:12.317
2024-11-21T05:57:41.790
Modified
CVSSv3.1: 8.8 (HIGH)
AV:A/AC:L/Au:N/C:C/I:C/A:C
6.5
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | br200_firmware | < 5.10.0.5 | Yes |
Hardware | netgear | br200 | - | No |
Operating System | netgear | br500_firmware | < 5.10.0.5 | Yes |
Hardware | netgear | br500 | - | No |
Operating System | netgear | d7800_firmware | < 1.0.1.60 | Yes |
Hardware | netgear | d7800 | - | No |
Operating System | netgear | ex6100v2_firmware | < 1.0.1.98 | Yes |
Hardware | netgear | ex6100v2 | - | No |
Operating System | netgear | ex6150v2_firmware | < 1.0.1.98 | Yes |
Hardware | netgear | ex6150v2 | - | No |
Operating System | netgear | ex6250_firmware | < 1.0.0.134 | Yes |
Hardware | netgear | ex6250 | - | No |
Operating System | netgear | ex6400_firmware | < 1.0.2.158 | Yes |
Hardware | netgear | ex6400 | - | No |
Operating System | netgear | ex6400v2_firmware | < 1.0.0.134 | Yes |
Hardware | netgear | ex6400v2 | - | No |
Operating System | netgear | ex6410_firmware | < 1.0.0.134 | Yes |
Hardware | netgear | ex6410 | - | No |
Operating System | netgear | ex6420_firmware | < 1.0.0.134 | Yes |
Hardware | netgear | ex6420 | - | No |
Operating System | netgear | ex7300_firmware | < 1.0.2.158 | Yes |
Hardware | netgear | ex7300 | - | No |
Operating System | netgear | ex7300v2_firmware | < 1.0.0.134 | Yes |
Hardware | netgear | ex7300v2 | - | No |
Operating System | netgear | ex7320_firmware | < 1.0.0.134 | Yes |
Hardware | netgear | ex7320 | - | No |
Operating System | netgear | ex7700_firmware | < 1.0.0.216 | Yes |
Hardware | netgear | ex7700 | - | No |
Operating System | netgear | ex8000_firmware | < 1.0.1.232 | Yes |
Hardware | netgear | ex8000 | - | No |
Operating System | netgear | lbr20_firmware | < 2.6.3.50 | Yes |
Hardware | netgear | lbr20 | - | No |
Operating System | netgear | r7800_firmware | < 1.0.2.80 | Yes |
Hardware | netgear | r7800 | - | No |
Operating System | netgear | r8900_firmware | < 1.0.5.28 | Yes |
Hardware | netgear | r8900 | - | No |
Operating System | netgear | r9000_firmware | < 1.0.5.28 | Yes |
Hardware | netgear | r9000 | - | No |
Operating System | netgear | rbk12_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk12 | - | No |
Operating System | netgear | rbk13_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk13 | - | No |
Operating System | netgear | rbk14_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk14 | - | No |
Operating System | netgear | rbk15_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk15 | - | No |
Operating System | netgear | rbk20_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbk20 | - | No |
Operating System | netgear | rbk23_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk23 | - | No |
Operating System | netgear | rbk40_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbk40 | - | No |
Operating System | netgear | rbk43_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbk43 | - | No |
Operating System | netgear | rbk43s_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbk43s | - | No |
Operating System | netgear | rbk44_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbk44 | - | No |
Operating System | netgear | rbk50_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk50 | - | No |
Operating System | netgear | rbk53_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbk53 | - | No |
Operating System | netgear | rbr10_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbr10 | - | No |
Operating System | netgear | rbr20_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbr20 | - | No |
Operating System | netgear | rbr40_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbr40 | - | No |
Operating System | netgear | rbr50_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbr50 | - | No |
Operating System | netgear | rbs10_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbs10 | - | No |
Operating System | netgear | rbs20_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbs20 | - | No |
Operating System | netgear | rbs40_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbs40 | - | No |
Operating System | netgear | rbs50_firmware | < 2.7.2.104 | Yes |
Hardware | netgear | rbs50 | - | No |
Operating System | netgear | rbs50y_firmware | < 2.6.2.104 | Yes |
Hardware | netgear | rbs50y | - | No |
Operating System | netgear | xr450_firmware | < 2.3.2.114 | Yes |
Hardware | netgear | xr450 | - | No |
Operating System | netgear | xr500_firmware | < 2.3.2.114 | Yes |
Hardware | netgear | xr500 | - | No |
Operating System | netgear | xr700_firmware | < 1.0.1.38 | Yes |
Hardware | netgear | xr700 | - | No |