PT-2020-14415 · NetGear · Netgear R6700
D4Rkn3Ss
·
Published
2020-07-28
·
Updated
2020-07-30
·
CVE-2020-15416
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR R6700 version 1.0.4.84 10.0.58
Description
This issue allows network-adjacent attackers to bypass authentication on affected installations. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this to execute code in the context of root.
Recommendations
For NETGEAR R6700 version 1.0.4.84 10.0.58, consider restricting access to the httpd service until a patch is available. As a temporary workaround, limiting the input data length to prevent buffer overflow may help mitigate the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear R6700