Presentation
NETGEAR published advisory PSV-2021-0323 covering a pre-authentication buffer overflow that affects a broad range of its routers, DSL modem routers, WiFi extenders and gateways. Exploitation requires network-adjacent access to the device (knowledge of the WiFi password, or a wired Ethernet connection); once adjacent, no authentication to the device is needed. On the R7000P, the issue was reported to NETGEAR by Jean-Jamil Khalifé (HDW Sec). NETGEAR additionally credits Stephen Fewer of Relyze Software, working through Trend Micro’s Zero Day Initiative (ZDI-22-519). The issue was assigned CVE-2022-27643.
Issue(s)
- Pre-authentication buffer overflow present across multiple NETGEAR products that share the same vulnerable code (PSV-2021-0323, CVE-2022-27643).
- Reachability: the attacker must be network-adjacent (know the WiFi password or have a wired Ethernet connection to the device). No application-level authentication is required thereafter.
- Root cause (per NVD and ZDI-22-519): the
upnpddaemon does not properly validate the length of user-supplied data when handling a SOAP requestSOAPActionheader before copying it into a buffer, a classic buffer overflow (CWE-120). - Impact: arbitrary code execution as
rooton affected devices. - Scoring note: NETGEAR self-rates the issue 7.3 (High) with a local vector. The NVD rates it 8.8 (High) with an adjacent-network vector (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected products and fixed firmware:
- Routers: R6400 (1.0.1.78), R6400v2 (1.0.4.126), R6700v3 (1.0.4.126), R6900P (1.3.3.148), R7000 (1.0.11.134), R7000P (1.3.3.148), R7850 (1.0.5.84), R7900P (1.4.3.88), R7960P (1.4.3.88), R8000 (1.0.4.84), R8000P (1.4.3.88), R8500 (1.0.2.158), RAX75 (1.0.6.138), RAX80 (1.0.6.138), RAX200 (1.0.6.138), RS400 (1.5.1.86), WNDR3400v3 (1.0.1.44), WNR3500Lv2 (1.2.0.72), XR300 (1.0.3.72).
- DSL modem routers: D6220 (1.0.0.80), D6400 (1.0.0.114), D7000v2 (1.0.0.80).
- WiFi extenders: EX3700 (1.0.0.96), EX3800 (1.0.0.96), EX6120 (1.0.0.68), EX6130 (1.0.0.48).
- Other: R7100LG (1.0.0.76), DC112A (1.0.0.64).
Firmware versions earlier than those listed are affected. NETGEAR recommends updating to the indicated version or later.
References
- NETGEAR security advisory (PSV-2021-0323): https://kb.netgear.com/000064720/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Multiple-Products-PSV-2021-0323
- CVE-2022-27643 (NVD): https://nvd.nist.gov/vuln/detail/CVE-2022-27643
- Zero Day Initiative (ZDI-22-519): https://www.zerodayinitiative.com/advisories/ZDI-22-519/