CVE-2022-27641
CVSS V2 None
CVSS V3 None
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15806.
Overview
- CVE ID
- CVE-2022-27641
- Assigner
- zdi-disclosures@trendmicro.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-03-29T19:15:08
- Last Modified Date
- 2023-04-05T15:42:17
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
AND | ||||
cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.1.68 | |
cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.1.90 | |
cpe:2.3:h:netgear:ex6200:v2:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:ex8000_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.1.240 | |
cpe:2.3:h:netgear:ex8000:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.1.0.112 | |
cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:r6230_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.1.0.112 | |
cpe:2.3:h:netgear:r6230:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.4.122 | |
cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.4.122 | |
cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.11.130 | |
cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:* | 1 | OR | 1.0.2.90 | |
cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:* | 0 | OR |
References
Reference URL | Reference Tags |
---|---|
https://kb.netgear.com/000064437/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Multiple-Products-PSV-2021-0278 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-22-544/ | Third Party Advisory VDB Entry |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-27641 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27641 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 03:46:39 | Added to TrackCVE | |||
2023-04-17 03:46:41 | Weakness Enumeration | new | ||
2023-04-17 05:04:31 | CVSS V3 information | new |