CVE-2021-20167
NETGEAR rax43 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2021-20167 has a selected CVSS score of 8.0 (high); EIP currently links 1 Nuclei template.
Description
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 19, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Netgear RAX43 | CVE List | 1.0.3.96 | affected |
Nuclei templates
1ProjectDiscoveryHIGHNetgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer OverrunCVSS 8
Netgear RAX43 version 1.0.3.96 contains a command injection and authentication bypass vulnerability. The readycloud_control.cgi CGI application is vulnerable to command injection in the name parameter. Additionally, the URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the application. Note: This vulnerability uses a combination of CVE-2021-20166 and CVE-2021-20167.
Impact
Authenticated attackers can execute arbitrary commands on the router, potentially compromising all network traffic and connected devices.
Remediation
Upgrade to newer release of the RAX43 firmware.
Source: ProjectDiscovery