CVE-2021-27256: (Pwn2Own) NETGEAR R7800 apply_save.cgi rc_service Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rcservice parameter provided to applysave.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12355.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rcservice parameter provided to applysave.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27256?
CVE-2021-27256 has been classified as a critical vulnerability due to its ability to allow arbitrary code execution by bypassing authentication.
How do I fix CVE-2021-27256?
To mitigate CVE-2021-27256, users should update their NETGEAR R7800 firmware to version 1.0.2.80 or later.
What devices are affected by CVE-2021-27256?
CVE-2021-27256 affects NETGEAR R7800 firmware version 1.0.2.76 and older, as well as several other NETGEAR devices listed in the advisory.
Can CVE-2021-27256 be exploited remotely?
CVE-2021-27256 can be exploited by network-adjacent attackers, requiring them to have access on the same network.
Is authentication still required to exploit CVE-2021-27256?
Yes, although authentication is required, the existing mechanism can be bypassed, making it critical to address this vulnerability.