CVE-2021-34865: NETGEAR Multiple Routers mini_httpd Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the minihttpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34865?
CVE-2021-34865 is a vulnerability that allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers.
How severe is CVE-2021-34865?
CVE-2021-34865 has a severity rating of 8.8 (high).
Which routers are affected by CVE-2021-34865?
Multiple routers from NETGEAR, including AC2100, AC2400, AC2600, D7000v1, R6220, R6230, R6260, R6330, R6350, R6700v2, R6800, R6850, R6900v2, R7200, R7350, R7400, and R7450, are affected by CVE-2021-34865.
How can the CVE-2021-34865 vulnerability be exploited?
The CVE-2021-34865 vulnerability can be exploited by network-adjacent attackers without requiring authentication.
Are there any available fixes for CVE-2021-34865?
Yes, NETGEAR has released firmware updates to address the CVE-2021-34865 vulnerability. It is recommended to update the firmware of affected routers to the latest version provided by NETGEAR.