CVE-2021-34947
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
07/05/2024
Last modified:
14/08/2025
Description
NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability.<br />
<br />
The specific flaw exists within the parsing of the soap_block_table file. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of root.<br />
. Was ZDI-CAN-13055.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* | 1.0.1.64 (excluding) | |
| cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex2700_firmware:*:*:*:*:*:*:*:* | 1.0.1.66 (excluding) | |
| cpe:2.3:h:netgear:ex2700:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex6100_firmware:*:*:*:*:*:*:*:* | 1.0.1.106 (excluding) | |
| cpe:2.3:h:netgear:ex6100:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex6150_firmware:*:*:*:*:*:*:*:* | 1.0.1.106 (excluding) | |
| cpe:2.3:h:netgear:ex6150:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:* | 1.0.1.86 (excluding) | |
| cpe:2.3:h:netgear:ex6200:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex6250_firmware:*:*:*:*:*:*:*:* | 1.0.0.146 (excluding) | |
| cpe:2.3:h:netgear:ex6250:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex6400_firmware:*:*:*:*:*:*:*:* | 1.0.2.164 (excluding) | |
| cpe:2.3:h:netgear:ex6400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ex6400v2_firmware:*:*:*:*:*:*:*:* | 1.0.0.146 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://kb.netgear.com/000064044/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2021-0129
- https://www.zerodayinitiative.com/advisories/ZDI-21-1116/
- https://kb.netgear.com/000064044/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2021-0129
- https://www.zerodayinitiative.com/advisories/ZDI-21-1116/



