CVE-2021-34980: NETGEAR R6260 setupwizard.cgi Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.781.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setupwizard.cgi page. When parsing the SOAPLOGINTOKEN environment variable, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-14107.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setupwizard.cgi page. When parsing the SOAPLOGINTOKEN environment variable, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34980?
The severity of CVE-2021-34980 is high with a CVSS score of 8.8.
How does CVE-2021-34980 allow attackers to execute arbitrary code?
CVE-2021-34980 allows network-adjacent attackers to execute arbitrary code by exploiting a stack-based buffer overflow vulnerability in the setupwizard.cgi page of NETGEAR R6260 routers.
Is authentication required to exploit CVE-2021-34980?
No, authentication is not required to exploit CVE-2021-34980.
What is the affected software for CVE-2021-34980?
The affected software for CVE-2021-34980 is NETGEAR R6260 routers with firmware version 1.1.0.78_1.0.1.
How can I fix CVE-2021-34980?
To fix CVE-2021-34980, it is recommended to update the firmware of NETGEAR R6260 routers to a version that addresses the vulnerability.