Lucene search

K
cveZdiCVE-2022-27645
HistoryMar 29, 2023 - 7:15 p.m.

CVE-2022-27645

2023-03-2919:15:08
CWE-306
CWE-697
zdi
web.nvd.nist.gov
26
cve-2022-27645
netgear
r6700v3
vulnerability
authentication bypass
code execution
readycloud_control.cgi
zdi-can-15762
nvd

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.6%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15762.

Affected configurations

Nvd
Vulners
Node
netgearlax20_firmwareRange<1.1.6.34
AND
netgearlax20Match-
Node
netgearr6400_firmwareRange<1.0.4.126
AND
netgearr6400Matchv2
Node
netgearr6700_firmwareRange<1.0.4.126
AND
netgearr6700Matchv3
Node
netgearr7000_firmwareRange<1.0.11.134
AND
netgearr7000Match-
Node
netgearr7850_firmwareRange<1.0.5.84
AND
netgearr7850Match-
Node
netgearr7900p_firmwareRange<1.4.3.88
AND
netgearr7900pMatch-
Node
netgearr7960p_firmwareRange<1.4.3.88
AND
netgearr7960pMatch-
Node
netgearr8000_firmwareRange<1.0.4.84
AND
netgearr8000Match-
Node
netgearr8000p_firmwareRange<1.4.3.88
AND
netgearr8000pMatch-
Node
netgearr8500_firmwareRange<1.0.2.158
AND
netgearr8500Match-
Node
netgearrax15_firmwareRange<1.0.10.110
AND
netgearrax15Match-
Node
netgearrax20_firmwareRange<1.0.10.110
AND
netgearrax20Match-
Node
netgearrax200_firmwareRange<1.0.6.138
AND
netgearrax200Match-
Node
netgearrax35_firmwareRange<1.0.10.110
AND
netgearrax35Matchv2
Node
netgearrax38_firmwareRange<1.0.10.110
AND
netgearrax38Matchv2
Node
netgearrax40_firmwareRange<1.0.10.110
AND
netgearrax40Matchv2
Node
netgearrax42_firmwareRange<1.0.10.110
AND
netgearrax42Match-
Node
netgearrax43_firmwareRange<1.0.10.110
AND
netgearrax43Match-
Node
netgearrax45_firmwareRange<1.0.10.110
AND
netgearrax45Match-
Node
netgearrax48_firmwareRange<1.0.10.110
AND
netgearrax48Match-
Node
netgearrax50_firmwareRange<1.0.10.110
AND
netgearrax50Match-
Node
netgearrax50s_firmwareRange<1.0.10.110
AND
netgearrax50sMatch-
Node
netgearrax75_firmwareRange<1.0.6.138
AND
netgearrax75Match-
VendorProductVersionCPE
netgearlax20_firmware*cpe:2.3:o:netgear:lax20_firmware:*:*:*:*:*:*:*:*
netgearlax20-cpe:2.3:h:netgear:lax20:-:*:*:*:*:*:*:*
netgearr6400_firmware*cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:*
netgearr6400v2cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:*
netgearr6700_firmware*cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:*
netgearr6700v3cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:*
netgearr7000_firmware*cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:*
netgearr7000-cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:*
netgearr7850_firmware*cpe:2.3:o:netgear:r7850_firmware:*:*:*:*:*:*:*:*
netgearr7850-cpe:2.3:h:netgear:r7850:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 461

CNA Affected

[
  {
    "vendor": "NETGEAR",
    "product": "R6700v3",
    "versions": [
      {
        "version": "1.0.4.120_10.0.91",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.6%

Related for CVE-2022-27645