CVE-2022-27645: (Pwn2Own) NETGEAR R6700v3 readycloud_control.cgi Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloudcontrol.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-27645.
What is the title of the vulnerability?
The title of the vulnerability is (Pwn2Own) NETGEAR R6700v3 readycloud_control.cgi Authentication Bypass Vulnerability.
How does this vulnerability affect NETGEAR R6700v3 routers?
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability.
What is the severity of CVE-2022-27645?
The severity of CVE-2022-27645 is high with a score of 8.8.
Are there any references for this vulnerability?
Yes, you can find more information about this vulnerability in the references provided: [Link 1](https://kb.netgear.com/000064722/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-and-Fixed-Wireless-Products-PSV-2021-0325), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-22-522/).