3.3
CVSSv2

CVE-2021-27257

Published: 05/03/2021 Updated: 17/03/2021
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

This vulnerability allows network-adjacent malicious users to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via FTP. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-12362.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgear br200_firmware

netgear br500_firmware

netgear d7800_firmware

netgear ex6100v2_firmware

netgear ex6150v2_firmware

netgear ex6250_firmware

netgear ex6400_firmware

netgear ex6400v2_firmware

netgear ex6410_firmware

netgear ex6420_firmware

netgear ex7300_firmware

netgear ex7300v2_firmware

netgear ex7320_firmware

netgear ex7700_firmware

netgear ex8000_firmware

netgear lbr20_firmware

netgear r7800_firmware

netgear r8900_firmware

netgear r9000_firmware

netgear rbk12_firmware

netgear rbk13_firmware

netgear rbk14_firmware

netgear rbk15_firmware

netgear rbk20_firmware

netgear rbk23_firmware

netgear rbk40_firmware

netgear rbk43_firmware

netgear rbk43s_firmware

netgear rbk44_firmware

netgear rbk50_firmware

netgear rbk53_firmware

netgear rbr10_firmware

netgear rbr20_firmware

netgear rbr40_firmware

netgear rbr50_firmware

netgear rbs10_firmware

netgear rbs20_firmware

netgear rbs40_firmware

netgear rbs50_firmware

netgear rbs50y_firmware

netgear xr450_firmware

netgear xr500_firmware

netgear xr700_firmware