Skip to main content
HDWSec
High CVE-2022-27643

NETGEAR Multiple Products upnpd Pre-Authentication Buffer Overflow (Pre-Auth RCE)

Severity
High
CVSS score
8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE number(s)
CVE-2022-27643
Vendor
NETGEAR
Product
Multiple models (R6400, R6700v3, R6900P, R7000, R7000P, R8000, RAX75/80/200, EX37xx, D6xxx, etc.)
Affected version(s)
Firmware prior to the per-model fixes (full list in the page body)
Fixed version(s)
Per model, e.g. R7000P 1.3.3.148, R7000 1.0.11.134, R8000 1.0.4.84 (full list in body)
Vulnerability type
Classic Buffer Overflow (CWE-120) in the upnpd SOAP/SOAPAction handler, pre-authentication RCE
Researchers
Jean-Jamil KHALIFÉ

Presentation

NETGEAR published advisory PSV-2021-0323 covering a pre-authentication buffer overflow that affects a broad range of its routers, DSL modem routers, WiFi extenders and gateways. Exploitation requires network-adjacent access to the device (knowledge of the WiFi password, or a wired Ethernet connection); once adjacent, no authentication to the device is needed. On the R7000P, the issue was reported to NETGEAR by Jean-Jamil Khalifé (HDW Sec). NETGEAR additionally credits Stephen Fewer of Relyze Software, working through Trend Micro’s Zero Day Initiative (ZDI-22-519). The issue was assigned CVE-2022-27643.

Issue(s)

  • Pre-authentication buffer overflow present across multiple NETGEAR products that share the same vulnerable code (PSV-2021-0323, CVE-2022-27643).
  • Reachability: the attacker must be network-adjacent (know the WiFi password or have a wired Ethernet connection to the device). No application-level authentication is required thereafter.
  • Root cause (per NVD and ZDI-22-519): the upnpd daemon does not properly validate the length of user-supplied data when handling a SOAP request SOAPAction header before copying it into a buffer, a classic buffer overflow (CWE-120).
  • Impact: arbitrary code execution as root on affected devices.
  • Scoring note: NETGEAR self-rates the issue 7.3 (High) with a local vector. The NVD rates it 8.8 (High) with an adjacent-network vector (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected products and fixed firmware:

  • Routers: R6400 (1.0.1.78), R6400v2 (1.0.4.126), R6700v3 (1.0.4.126), R6900P (1.3.3.148), R7000 (1.0.11.134), R7000P (1.3.3.148), R7850 (1.0.5.84), R7900P (1.4.3.88), R7960P (1.4.3.88), R8000 (1.0.4.84), R8000P (1.4.3.88), R8500 (1.0.2.158), RAX75 (1.0.6.138), RAX80 (1.0.6.138), RAX200 (1.0.6.138), RS400 (1.5.1.86), WNDR3400v3 (1.0.1.44), WNR3500Lv2 (1.2.0.72), XR300 (1.0.3.72).
  • DSL modem routers: D6220 (1.0.0.80), D6400 (1.0.0.114), D7000v2 (1.0.0.80).
  • WiFi extenders: EX3700 (1.0.0.96), EX3800 (1.0.0.96), EX6120 (1.0.0.68), EX6130 (1.0.0.48).
  • Other: R7100LG (1.0.0.76), DC112A (1.0.0.64).

Firmware versions earlier than those listed are affected. NETGEAR recommends updating to the indicated version or later.

References

Our R&D hunts for vulnerabilities.

Zero-day research, reverse engineering, coordinated disclosure: discover our R&D team.