CVE-2021-27254: (Pwn2Own) NETGEAR Nighthawk R7800 Use of Hard-coded Password Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the applysave.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to execute arbitrary code in the context of root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27254?
CVE-2021-27254 has been classified as critical due to its ability to allow unauthenticated remote access to the affected devices.
How do I fix CVE-2021-27254?
To mitigate CVE-2021-27254, users should immediately update their NETGEAR R7800 firmware to the latest version provided by NETGEAR.
Which devices are affected by CVE-2021-27254?
CVE-2021-27254 specifically affects the NETGEAR R7800 router, along with certain firmware versions of other NETGEAR devices.
What exploit can be performed using CVE-2021-27254?
CVE-2021-27254 allows attackers to bypass authentication and gain unauthorized access to configuration settings on NETGEAR R7800 devices.
Is authentication required to exploit CVE-2021-27254?
No, CVE-2021-27254 does not require any authentication, making it particularly dangerous for network-adjacent attackers.