What’s Driving The Increase In Demand for Compromised Assessments?
January 3, 2022Rewterz Threat Alert – Quasar RAT – Active IOCs
January 3, 2022What’s Driving The Increase In Demand for Compromised Assessments?
January 3, 2022Rewterz Threat Alert – Quasar RAT – Active IOCs
January 3, 2022Severity
High
Analysis Summary
CVE-2021-20166
Netgear RAX43 is vulnerable to a buffer overflow, caused by improper bounds checking by the URL parsing functionality in the cgi-bin endpoint of the router containers. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVE-2021-20167
Netgear RAX43 could allow a remote attacker to execute arbitrary commands on the system, caused by a command injection vulnerability in the readycloud cgi application. An attacker could exploit this vulnerability using the name parameter to inject and execute arbitrary commands on the system.
CVE-2021-20168
Netgear RAX43 could allow a local attacker to execute arbitrary commands on the system, caused by insufficient protections to the UART interface. An attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2021-20169
Netgear RAX43 could allow a local attacker to obtain sensitive information, caused by the failure to utilize secure communications to the web interface. An attacker could exploit this vulnerability to transmit the username and password in cleartext to obtain sensitive information.
CVE-2021-20170
Netgear RAX43 contains hardcoded credentials. By unzipping the configuration using this password, an attacker could exploit this vulnerability to manipulate configuration backups.
CVE-2021-20171
Netgear RAX43 could allow a local attacker to obtain sensitive information, caused by the storage of usernames and passwords in plaintext. An attacker could exploit this vulnerability to obtain the admin password.
CVE-2021-20172
Netgear Genie Installer for macOS could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper permissions in the “postinstall” script included in the installer. An attacker could exploit this vulnerability to gain elevated privileges on the system.
CVE-2021-20173
NETGEAR Nighthawk R6700 could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by an error in the update functionality. By triggering a system update check via the SOAP interface, an attacker could exploit this vulnerability using preconfigured values to inject and execute arbitrary commands on the system.
CVE-2021-20174
NETGEAR Nighthawk R6700 could allow a remote attacker to obtain sensitive information, caused by the transmittal of usernames and passwords in cleartext. An attacker could exploit this vulnerability to obtain sensitive information.
CVE-2021-20175
NETGEAR Nighthawk R6700 could allow a remote attacker to obtain sensitive information, caused by the transmittal of usernames and passwords in cleartext. An attacker could exploit this vulnerability to obtain sensitive information.
CVE-2021-23147
NETGEAR Nighthawk R6700 could allow a local attacker to execute arbitrary commands on the system, caused by insufficient protections for the UART console. By using a serial connection, an attacker could exploit this vulnerability to execute commands as the root user without authentication.
CVE-2021-45077
NETGEAR Nighthawk R6700 could allow a local attacker to obtain sensitive information, caused by the storage of usernames and passwords for the device’s associated services in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.
CVE-2021-45732
NETGEAR Nighthawk R6700 contains default hardcoded credentials. A remote authenticated attacker could exploit this vulnerability using hardcoded encryption routines gain access to manipulate configuration backups.
Impact
- Buffer Overflow
- Command Execution
- Information Disclosure
- Unauthorized Access
- Privilege Escalation
Affected Vendors
NETGEAR
Affected Products
- NETGEAR RAX43
- NETGEAR Genie Installer for macOS
- NETGEAR Nighthawk R6700 1.0.4.120
Remediation
Refer to NETGEAR Security Advisory for patch, upgrade, or suggested workaround information.
Netgear RAX43
Netgear Genie Installer for macOS
NETGEAR Nighthawk R6700