Aller au contenu principal
HDWSec
High CVE-2022-27643

NETGEAR Multiple Products upnpd Pre-Authentication Buffer Overflow (Pre-Auth RCE)

Sévérité
High
Score CVSS
8.8CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiants CVE
CVE-2022-27643
Éditeur
NETGEAR
Produit
Multiple models (R6400, R6700v3, R6900P, R7000, R7000P, R8000, RAX75/80/200, EX37xx, D6xxx, etc.)
Versions affectées
Firmware prior to the per-model fixes (full list in the page body)
Version corrigée
Per model, e.g. R7000P 1.3.3.148, R7000 1.0.11.134, R8000 1.0.4.84 (full list in body)
Type de vulnérabilité
Classic Buffer Overflow (CWE-120) in the upnpd SOAP/SOAPAction handler, pre-authentication RCE
Chercheurs
Jean-Jamil KHALIFÉ

Presentation

NETGEAR published advisory PSV-2021-0323 covering a pre-authentication buffer overflow that affects a broad range of its routers, DSL modem routers, WiFi extenders and gateways. Exploitation requires network-adjacent access to the device (knowledge of the WiFi password, or a wired Ethernet connection); once adjacent, no authentication to the device is needed. On the R7000P, the issue was reported to NETGEAR by Jean-Jamil Khalifé (HDW Sec). NETGEAR additionally credits Stephen Fewer of Relyze Software, working through Trend Micro’s Zero Day Initiative (ZDI-22-519). The issue was assigned CVE-2022-27643.

Issue(s)

  • Pre-authentication buffer overflow present across multiple NETGEAR products that share the same vulnerable code (PSV-2021-0323, CVE-2022-27643).
  • Reachability: the attacker must be network-adjacent (know the WiFi password or have a wired Ethernet connection to the device). No application-level authentication is required thereafter.
  • Root cause (per NVD and ZDI-22-519): the upnpd daemon does not properly validate the length of user-supplied data when handling a SOAP request SOAPAction header before copying it into a buffer, a classic buffer overflow (CWE-120).
  • Impact: arbitrary code execution as root on affected devices.
  • Scoring note: NETGEAR self-rates the issue 7.3 (High) with a local vector. The NVD rates it 8.8 (High) with an adjacent-network vector (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected products and fixed firmware:

  • Routers: R6400 (1.0.1.78), R6400v2 (1.0.4.126), R6700v3 (1.0.4.126), R6900P (1.3.3.148), R7000 (1.0.11.134), R7000P (1.3.3.148), R7850 (1.0.5.84), R7900P (1.4.3.88), R7960P (1.4.3.88), R8000 (1.0.4.84), R8000P (1.4.3.88), R8500 (1.0.2.158), RAX75 (1.0.6.138), RAX80 (1.0.6.138), RAX200 (1.0.6.138), RS400 (1.5.1.86), WNDR3400v3 (1.0.1.44), WNR3500Lv2 (1.2.0.72), XR300 (1.0.3.72).
  • DSL modem routers: D6220 (1.0.0.80), D6400 (1.0.0.114), D7000v2 (1.0.0.80).
  • WiFi extenders: EX3700 (1.0.0.96), EX3800 (1.0.0.96), EX6120 (1.0.0.68), EX6130 (1.0.0.48).
  • Other: R7100LG (1.0.0.76), DC112A (1.0.0.64).

Firmware versions earlier than those listed are affected. NETGEAR recommends updating to the indicated version or later.

References

Notre R&D traque les vulnérabilités.

Recherche de 0-day, reverse engineering, divulgation coordonnée : découvrez notre pôle R&D.