PT-2021-6474 · NetGear · Netgear Xr300+14

Stephen Fewer

·

Published

2021-12-03

·

Updated

2023-04-05

·

CVE-2022-27643

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R6400 versions prior to the fixed version NETGEAR R6400v2 versions prior to the fixed version NETGEAR R6700v3 version 1.0.4.120 10.0.91 NETGEAR R6900P versions prior to the fixed version NETGEAR R7000 versions prior to the fixed version NETGEAR R7000P versions prior to the fixed version NETGEAR R8500 versions prior to the fixed version NETGEAR RS400 versions prior to the fixed version NETGEAR WNDR3400v3 versions prior to the fixed version NETGEAR WNR3500Lv2 versions prior to the fixed version NETGEAR XR300 versions prior to the fixed version NETGEAR D6220 versions prior to the fixed version NETGEAR D6400 versions prior to the fixed version NETGEAR D7000v2 versions prior to the fixed version NETGEAR R7100LG versions prior to the fixed version NETGEAR DC112A versions prior to the fixed version
Description The issue is related to a buffer overflow due to the lack of validation of the length of user-supplied data when handling SOAP requests, specifically when parsing the SOAPAction header. This allows an attacker to execute arbitrary code in the context of root without requiring authentication. The vulnerability can be exploited by network-adjacent attackers.
Recommendations For NETGEAR R6400, update to a version that fixes the vulnerability. For NETGEAR R6400v2, update to a version that fixes the vulnerability. For NETGEAR R6700v3 version 1.0.4.120 10.0.91, update to a version that fixes the vulnerability. For NETGEAR R6900P, update to a version that fixes the vulnerability. For NETGEAR R7000, update to a version that fixes the vulnerability. For NETGEAR R7000P, update to a version that fixes the vulnerability. For NETGEAR R8500, update to a version that fixes the vulnerability. For NETGEAR RS400, update to a version that fixes the vulnerability. For NETGEAR WNDR3400v3, update to a version that fixes the vulnerability. For NETGEAR WNR3500Lv2, update to a version that fixes the vulnerability. For NETGEAR XR300, update to a version that fixes the vulnerability. For NETGEAR D6220, update to a version that fixes the vulnerability. For NETGEAR D6400, update to a version that fixes the vulnerability. For NETGEAR D7000v2, update to a version that fixes the vulnerability. For NETGEAR R7100LG, update to a version that fixes the vulnerability. For NETGEAR DC112A, update to a version that fixes the vulnerability. As a temporary workaround, consider disabling the handling of SOAP requests until a patch is available. Restrict access to the vulnerable upnpd service to minimize the risk of exploitation. Avoid using the SOAPAction header in SOAP requests to the affected routers until the issue is resolved.

Fix

Buffer Overflow

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-01712
CVE-2022-27643
ZDI-22-519

Affected Products

Netgear R6220
Netgear R6400
Netgear D7000V2
Netgear Dc112A
Netgear R6400V2
Netgear R6700V3
Netgear R6900P
Netgear R7000
Netgear R7000P
Netgear R7100Lg
Netgear R8500
Netgear Rs400
Netgear Wndr3400V3
Netgear Wnr3500Lv2
Netgear Xr300