First published: Wed Mar 29 2023(Updated: )
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R6700v3 firmware | ||
NETGEAR LAX20 firmware | <1.1.6.34 | |
NETGEAR LAX20 | ||
NETGEAR R6400 firmware | <1.0.4.126 | |
NETGEAR R6400 firmware | =v2 | |
NETGEAR R6700 firmware | <1.0.4.126 | |
NETGEAR R6700v1 firmware | =v3 | |
Netgear Nighthawk R7000 Firmware | <1.0.11.134 | |
NETGEAR Nighthawk R7000 | ||
NETGEAR R7850 | <1.0.5.84 | |
NETGEAR R7850 firmware | ||
NETGEAR R7900P firmware | <1.4.3.88 | |
NETGEAR R7900P firmware | ||
NETGEAR R7960P firmware | <1.4.3.88 | |
NETGEAR R7960P firmware | ||
NETGEAR R8000 firmware | <1.0.4.84 | |
NETGEAR R8000 firmware | ||
NETGEAR R8000P | <1.4.3.88 | |
NETGEAR R8000P firmware | ||
NETGEAR R8500 | <1.0.2.158 | |
NETGEAR R8500 | ||
NETGEAR RAX15 firmware | <1.0.10.110 | |
NETGEAR RAX15 firmware | ||
NETGEAR RAX20 firmware | <1.0.10.110 | |
NETGEAR RAX20 firmware | ||
NETGEAR RAX200 firmware | <1.0.6.138 | |
NETGEAR RAX200 firmware | ||
NETGEAR RAX35 firmware | <1.0.10.110 | |
Netgear RAX35 | =v2 | |
NETGEAR RAX38v2 Firmware | <1.0.10.110 | |
NETGEAR RAX38v2 Firmware | =v2 | |
NETGEAR RAX40 firmware | <1.0.10.110 | |
NETGEAR RAX40 firmware | =v2 | |
NETGEAR RAX42 | <1.0.10.110 | |
NETGEAR RAX42 Firmware | ||
Netgear RAX43 | <1.0.10.110 | |
Netgear RAX43 | ||
NETGEAR RAX45 firmware | <1.0.10.110 | |
NETGEAR RAX45 firmware | ||
NETGEAR RAX48 | <1.0.10.110 | |
NETGEAR RAX48 Firmware | ||
NETGEAR RAX50 | <1.0.10.110 | |
NETGEAR RAX50 | ||
NETGEAR RAX50 | <1.0.10.110 | |
NETGEAR RAX50 | ||
NETGEAR RAX75 firmware | <1.0.6.138 | |
NETGEAR RAX75 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-27645.
The title of the vulnerability is (Pwn2Own) NETGEAR R6700v3 readycloud_control.cgi Authentication Bypass Vulnerability.
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability.
The severity of CVE-2022-27645 is high with a score of 8.8.
Yes, you can find more information about this vulnerability in the references provided: [Link 1](https://kb.netgear.com/000064722/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-and-Fixed-Wireless-Products-PSV-2021-0325), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-22-522/).