CVE-2022-27641

CVSS V2 None CVSS V3 None
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15806.
Overview
  • CVE ID
  • CVE-2022-27641
  • Assigner
  • zdi-disclosures@trendmicro.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-29T19:15:08
  • Last Modified Date
  • 2023-04-05T15:42:17
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.1.68
cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.1.90
cpe:2.3:h:netgear:ex6200:v2:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:ex8000_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.1.240
cpe:2.3:h:netgear:ex8000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.112
cpe:2.3:h:netgear:r6220:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6230_firmware:*:*:*:*:*:*:*:* 1 OR 1.1.0.112
cpe:2.3:h:netgear:r6230:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.4.122
cpe:2.3:h:netgear:r6400:v2:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.4.122
cpe:2.3:h:netgear:r6700:v3:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.11.130
cpe:2.3:h:netgear:r7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:* 1 OR 1.0.2.90
cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:* 0 OR
History
Created Old Value New Value Data Type Notes
2023-04-17 03:46:39 Added to TrackCVE
2023-04-17 03:46:41 Weakness Enumeration new
2023-04-17 05:04:31 CVSS V3 information new