CVE-2021-34947: NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability

Published May 7, 2024
·
Updated

NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the parsing of the soapblocktable file. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-13055.

Affected Software

83 affected components
Netgear R7800
All of the following
Netgear D7800 Firmware<1.0.1.64
Netgear D7800
All of the following
Netgear Ex2700 Firmware<1.0.1.66
Netgear EX2700
All of the following
Netgear Ex6100 Firmware<1.0.1.106
Netgear EX6100=v2
All of the following
Netgear Ex6150 Firmware<1.0.1.106
Netgear EX6150=v2
All of the following
Netgear Ex6200 Firmware<1.0.1.86
Netgear EX6200=v2
All of the following
Netgear Ex6250 Firmware<1.0.0.146
Netgear EX6250
All of the following
Netgear Ex6400 Firmware<1.0.2.164
Netgear EX6400
All of the following
Netgear Ex6400v2 Firmware<1.0.0.146
Netgear EX6400v2
All of the following
Netgear Ex6410 Firmware<1.0.0.146
Netgear EX6410
All of the following
Netgear Ex6420 Firmware<1.0.0.146
Netgear EX6420
All of the following
Netgear Ex6500v1 Firmware<1.0.0.146
Netgear Ex6500v1
All of the following
Netgear Ex7300 Firmware<1.0.2.164
Netgear EX7300
All of the following
Netgear Ex7300v2 Firmware<1.0.0.146
Netgear EX7300v2
All of the following
Netgear Ex7320 Firmware<1.0.0.146
Netgear EX7320
All of the following
Netgear Ex7700 Firmware<1.0.0.222
Netgear EX7700
All of the following
Netgear Ex8000 Firmware<1.0.1.238
Netgear EX8000
All of the following
Netgear Lbr1020 Firmware<2.6.5.32
Netgear LBR1020
All of the following
Netgear Lbr20 Firmware<2.6.5.32
Netgear LBR20
All of the following
Netgear R6700ax Firmware<1.0.5.108
Netgear R6700AX
All of the following
Netgear R7800 firmware<1.0.2.84
Netgear R7800
All of the following
Netgear R8900 Firmware<1.0.5.36
Netgear R8900
All of the following
Netgear R9000 Firmware<1.0.5.36
Netgear R9000
All of the following
Netgear Rax10 Firmware<1.0.5.108
Netgear RAX10
All of the following
Netgear Rax120 Firmware<1.2.2.24
Netgear RAX120
All of the following
Netgear Rax120v2 Firmware<1.2.2.24
Netgear RAX120v2
All of the following
Netgear Rax70 Firmware<1.0.5.108
Netgear RAX70
All of the following
Netgear Rax78 Firmware<1.0.5.108
Netgear RAX78
All of the following
Netgear Rbr10 Firmware<2.7.4.24
Netgear RBR10
All of the following
Netgear Rbr20 Firmware<2.7.4.24
Netgear RBR20
All of the following
Netgear Rbr40 Firmware<2.7.4.24
Netgear RBR40
All of the following
Netgear Rbr50 Firmware<2.7.4.24
Netgear RBR50
All of the following
Netgear Rbs10 Firmware<2.7.4.24
Netgear RBS10
All of the following
Netgear Rbs20 Firmware<2.7.4.24
Netgear RBS20
All of the following
Netgear Rbs40 Firmware<2.7.4.24
Netgear RBS40
All of the following
Netgear Rbs50 Firmware<2.7.4.24
Netgear RBS50
All of the following
Netgear Rbs50y Firmware<2.7.4.12
Netgear RBS50Y
All of the following
Netgear Wn3000rpv2 Firmware<1.0.0.88
Netgear WN3000RPv2
All of the following
Netgear Wnr2000v5 Firmware<1.0.0.78
Netgear WNR2000v5
All of the following
Netgear Xr450 Firmware<2.3.2.130
Netgear XR450
All of the following
Netgear Xr500 Firmware<2.3.2.130
Netgear XR500
All of the following
Netgear Xr700 Firmware<1.0.1.44
Netgear XR700

Event History

May 7, 2024
CVE Published
via MITRE·10:54 PM
Data Sourced
via MITRE·10:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 23, 2025
Advisory Published
via ZDI·03:37 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-34947?

CVE-2021-34947 is categorized as a critical vulnerability due to its potential for remote code execution without authentication.

2

How do I fix CVE-2021-34947?

To fix CVE-2021-34947, update your NETGEAR R7800 router to the latest firmware version provided by the manufacturer.

3

Who can exploit CVE-2021-34947?

CVE-2021-34947 can be exploited by network-adjacent attackers without requiring authentication.

4

What are the implications of CVE-2021-34947 on NETGEAR R7800 routers?

The implications include the potential for attackers to execute arbitrary code, which can lead to full system compromise.

5

Is CVE-2021-34947 specific only to NETGEAR R7800 routers?

Yes, CVE-2021-34947 specifically affects NETGEAR R7800 routers and may not impact other models.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203