CVE-2022-27643
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process does not properly validate the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15692.
Published:Mar 29, 2023
Last Modified:Feb 18, 2025
EPS:Mar 29, 2023
EPSS Score:0.04651
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Netgear
Product
D6220
Netgear
D6220
Vendor
Netgear
Product
D6220 Firmware
Netgear
D6220 Firmware
Vendor
Netgear
Product
D6400
Netgear
D6400
Vendor
Netgear
Product
D6400 Firmware
Netgear
D6400 Firmware
Vendor
Netgear
Product
D7000v2
Netgear
D7000v2
Vendor
Netgear
Product
D7000v2 Firmware
Netgear
D7000v2 Firmware
Vendor
Netgear
Product
Dc112a
Netgear
Dc112a
Vendor
Netgear
Product
Dc112a Firmware
Netgear
Dc112a Firmware
Vendor
Netgear
Product
Ex3700
Netgear
Ex3700
Vendor
Netgear
Product
Ex3700 Firmware
Netgear
Ex3700 Firmware
Vendor
Netgear
Product
Ex3800
Netgear
Ex3800
Vendor
Netgear
Product
Ex3800 Firmware
Netgear
Ex3800 Firmware
Vendor
Netgear
Product
Ex6120
Netgear
Ex6120
Vendor
Netgear
Product
Ex6120 Firmware
Netgear
Ex6120 Firmware
Vendor
Netgear
Product
Ex6130
Netgear
Ex6130
Vendor
Netgear
Product
Ex6130 Firmware
Netgear
Ex6130 Firmware
Vendor
Netgear
Product
R6400
Netgear
R6400
Vendor
Netgear
Product
R6400 Firmware
Netgear
R6400 Firmware
Vendor
Netgear
Product
R6700
Netgear
R6700
Vendor
Netgear
Product
R6700 Firmware
Netgear
R6700 Firmware
Vendor
Netgear
Product
R6900p
Netgear
R6900p
Vendor
Netgear
Product
R6900p Firmware
Netgear
R6900p Firmware
Vendor
Netgear
Product
R7000
Netgear
R7000
Vendor
Netgear
Product
R7000 Firmware
Netgear
R7000 Firmware
Vendor
Netgear
Product
R7000p
Netgear
R7000p
Vendor
Netgear
Product
R7000p Firmware
Netgear
R7000p Firmware
Vendor
Netgear
Product
R7100lg
Netgear
R7100lg
Vendor
Netgear
Product
R7100lg Firmware
Netgear
R7100lg Firmware
Vendor
Netgear
Product
R7850
Netgear
R7850
Vendor
Netgear
Product
R7850 Firmware
Netgear
R7850 Firmware
Vendor
Netgear
Product
R7900p
Netgear
R7900p
Vendor
Netgear
Product
R7900p Firmware
Netgear
R7900p Firmware
Vendor
Netgear
Product
R7960p
Netgear
R7960p
Vendor
Netgear
Product
R7960p Firmware
Netgear
R7960p Firmware
Vendor
Netgear
Product
R8000
Netgear
R8000
Vendor
Netgear
Product
R8000 Firmware
Netgear
R8000 Firmware
Vendor
Netgear
Product
R8000p
Netgear
R8000p
Vendor
Netgear
Product
R8000p Firmware
Netgear
R8000p Firmware
Vendor
Netgear
Product
R8500
Netgear
R8500
Vendor
Netgear
Product
R8500 Firmware
Netgear
R8500 Firmware
Vendor
Netgear
Product
Rax200
Netgear
Rax200
Vendor
Netgear
Product
Rax200 Firmware
Netgear
Rax200 Firmware
Vendor
Netgear
Product
Rax75
Netgear
Rax75
Vendor
Netgear
Product
Rax75 Firmware
Netgear
Rax75 Firmware
Vendor
Netgear
Product
Rax80
Netgear
Rax80
Vendor
Netgear
Product
Rax80 Firmware
Netgear
Rax80 Firmware
Vendor
Netgear
Product
Rs400
Netgear
Rs400
Vendor
Netgear
Product
Rs400 Firmware
Netgear
Rs400 Firmware
Vendor
Netgear
Product
Wndr3400
Netgear
Wndr3400
Vendor
Netgear
Product
Wndr3400 Firmware
Netgear
Wndr3400 Firmware
Vendor
Netgear
Product
Wnr3500l
Netgear
Wnr3500l
Vendor
Netgear
Product
Wnr3500l Firmware
Netgear
Wnr3500l Firmware
Vendor
Netgear
Product
Xr300
Netgear
Xr300
Vendor
Netgear
Product
Xr300 Firmware
Netgear
Xr300 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
