kb.netgear.com
https://kb.netgear.com/000064721/Security-Advisory-for-Multiple-Vulnerabilities-on-Multiple-Products-PSV-2021-0324 CVE-2022-27646
HIGH
Record summary
CVE-2022-27646 has a selected CVSS score of 8.8 (high).
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled daemon. A crafted circleinfo.txt file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15879.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
R6700v3Browse NETGEAR / R6700v3 | CVE List | 1.0.4.120_10.0.91 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-27646 zerodayinitiative.com
https://www.zerodayinitiative.com/advisories/ZDI-22-523