Record summary

CVE-2021-20167 has a selected CVSS score of 8.0 (high); EIP currently links 1 Nuclei template.

Description

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 19, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Netgear RAX43

CVE List1.0.3.96affected

Nuclei templates

1
ProjectDiscoveryHIGHNetgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer OverrunCVSS 8

Netgear RAX43 version 1.0.3.96 contains a command injection and authentication bypass vulnerability. The readycloud_control.cgi CGI application is vulnerable to command injection in the name parameter. Additionally, the URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the application. Note: This vulnerability uses a combination of CVE-2021-20166 and CVE-2021-20167.

Impact

Authenticated attackers can execute arbitrary commands on the router, potentially compromising all network traffic and connected devices.

Remediation

Upgrade to newer release of the RAX43 firmware.

WeaknessesCWE-77
Authorsgy741
Template tagscve2021cvetenablenetgearrceroutervkevvuln
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:netgear:rax43_firmware:1.0.3.96:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2