CVE-2021-27252: (Pwn2Own) NETGEAR R7800 udchpd DHCP_REQUEST Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the vendorspecific DHCP opcode. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12216.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the vendorspecific DHCP opcode. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27252?
CVE-2021-27252 is considered a critical vulnerability as it allows unauthenticated network-adjacent attackers to execute arbitrary code.
How do I fix CVE-2021-27252?
To mitigate CVE-2021-27252, upgrade your NETGEAR R7800 firmware to the latest version, specifically 1.0.2.80 or later.
Which devices are affected by CVE-2021-27252?
CVE-2021-27252 specifically affects NETGEAR R7800 firmware version 1.0.2.76 and earlier.
Is authentication required to exploit CVE-2021-27252?
No, authentication is not required to exploit CVE-2021-27252, making it particularly dangerous.
What is the nature of the vulnerability in CVE-2021-27252?
The vulnerability in CVE-2021-27252 is due to improper handling of vendor-specific DHCP messages.