PT-2021-6477 · NetGear · Netgear Rax15+13

Xiaochen Zou

+2

·

Published

2021-12-01

·

Updated

2023-04-28

·

CVE-2022-27645

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R6400v2 version not specified NETGEAR R6700v3 version not specified NETGEAR R7000 version not specified NETGEAR R8500 version not specified NETGEAR RAX15 version not specified NETGEAR RAX20 version not specified NETGEAR RAX35v2 version not specified NETGEAR RAX38v2 version not specified NETGEAR RAX40v2 version not specified NETGEAR RAX42 version not specified NETGEAR RAX43 version not specified NETGEAR RAX45 version not specified NETGEAR RAX48 version not specified NETGEAR RAX50 version not specified NETGEAR RAX50S version not specified NETGEAR LAX20 version not specified
Description This issue allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR routers. The specific flaw exists within the readycloud control.cgi file, resulting from the lack of authentication prior to allowing access to functionality. An attacker can leverage this issue to execute code in the context of root. The exploitation of this issue may allow a remote attacker to bypass authentication via an alternative name.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-01719
CVE-2022-27645
ZDI-22-522

Affected Products

Netgear Rax20
Netgear R6400V2
Netgear R6700V3
Netgear R7000
Netgear R8500
Netgear Rax15
Netgear Rax35V2
Netgear Rax38V2
Netgear Rax40V2
Netgear Rax42
Netgear Rax43
Netgear Rax45
Netgear Rax48
Netgear Rax50