CVE-2021-34947: NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability
NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the parsing of the soapblocktable file. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-13055.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34947?
CVE-2021-34947 is categorized as a critical vulnerability due to its potential for remote code execution without authentication.
How do I fix CVE-2021-34947?
To fix CVE-2021-34947, update your NETGEAR R7800 router to the latest firmware version provided by the manufacturer.
Who can exploit CVE-2021-34947?
CVE-2021-34947 can be exploited by network-adjacent attackers without requiring authentication.
What are the implications of CVE-2021-34947 on NETGEAR R7800 routers?
The implications include the potential for attackers to execute arbitrary code, which can lead to full system compromise.
Is CVE-2021-34947 specific only to NETGEAR R7800 routers?
Yes, CVE-2021-34947 specifically affects NETGEAR R7800 routers and may not impact other models.