Lucene search

K
zdiSungur LabsZDI-21-1274
HistoryOct 29, 2021 - 12:00 a.m.

NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability

2021-10-2900:00:00
Sungur Labs
www.zerodayinitiative.com
20
netgear
routers
buffer overflow
httpd
remote code execution
tcp port 80
stack-based buffer
root access

EPSS

0.001

Percentile

16.2%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. When parsing the strings file, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.

EPSS

0.001

Percentile

16.2%

Related for ZDI-21-1274