PT-2021-4644 · NetGear · Netgear R9000+9

Hoang Thach Nguyen

·

Published

2021-05-26

·

Updated

2025-08-14

·

CVE-2021-34947

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R6700AX versions (affected versions not specified) NETGEAR R7800 versions (affected versions not specified) NETGEAR R8900 versions (affected versions not specified) NETGEAR R9000 versions (affected versions not specified) NETGEAR RAX10 versions (affected versions not specified) NETGEAR RAX120 versions (affected versions not specified) NETGEAR RAX120v2 versions (affected versions not specified) NETGEAR RAX70 versions (affected versions not specified) NETGEAR RAX78 versions (affected versions not specified) NETGEAR XR700 versions (affected versions not specified)
Description The issue is related to a buffer overflow when parsing the soap block table file, allowing an attacker to execute arbitrary code on affected installations of NETGEAR routers. The flaw exists due to the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of root. No authentication is required to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2021-05333
CVE-2021-34947
ZDI-21-1116

Affected Products

Netgear R6700
Netgear R7800
Netgear R8900
Netgear R9000
Netgear Rax10
Netgear Rax120
Netgear Rax120V2
Netgear Rax70
Netgear Rax78
Netgear Xr700