CVE-2021-27257

MEDIUM

NETGEAR R7800 <1.0.2.76 - Info Disclosure

Title source: llm
STIX 2.1

Description

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via FTP. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-12362.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 17.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (43)
netgear/br200_firmware < 5.10.0.5
netgear/br500_firmware < 5.10.0.5
netgear/d7800_firmware < 1.0.1.60
netgear/ex6100v2_firmware < 1.0.1.98
netgear/ex6150v2_firmware < 1.0.1.98
netgear/ex6250_firmware < 1.0.0.134
netgear/ex6400_firmware < 1.0.2.158
netgear/ex6400v2_firmware < 1.0.0.134
netgear/ex6410_firmware < 1.0.0.134
netgear/ex6420_firmware < 1.0.0.134
... and 33 more
Published Mar 05, 2021
Tracked Since Feb 18, 2026