PT-2021-4644 · NetGear · Netgear R9000+9
Hoang Thach Nguyen
·
Published
2021-05-26
·
Updated
2025-08-14
·
CVE-2021-34947
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR R6700AX versions (affected versions not specified)
NETGEAR R7800 versions (affected versions not specified)
NETGEAR R8900 versions (affected versions not specified)
NETGEAR R9000 versions (affected versions not specified)
NETGEAR RAX10 versions (affected versions not specified)
NETGEAR RAX120 versions (affected versions not specified)
NETGEAR RAX120v2 versions (affected versions not specified)
NETGEAR RAX70 versions (affected versions not specified)
NETGEAR RAX78 versions (affected versions not specified)
NETGEAR XR700 versions (affected versions not specified)
Description
The issue is related to a buffer overflow when parsing the
soap block table file, allowing an attacker to execute arbitrary code on affected installations of NETGEAR routers. The flaw exists due to the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of root. No authentication is required to exploit this vulnerability.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear R6700
Netgear R7800
Netgear R8900
Netgear R9000
Netgear Rax10
Netgear Rax120
Netgear Rax120V2
Netgear Rax70
Netgear Rax78
Netgear Xr700