← All CVEs

CVE-2021-40847

high · 8.1

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR to obtain version information and updates to the circled daemon and its filtering database. However, database updates from NETGEAR are unsigned and downloaded via cleartext HTTP. As such, an attacker with the ability to perform a MitM attack on the device can respond to circled update requests with a crafted, compressed database file, the extraction of which gives the attacker the ability to overwrite executable files with attacker-controlled code. This affects R6400v2 1.0.4.106, R6700 1.0.2.16, R6700v3 1.0.4.106, R6900 1.0.2.16, R6900P 1.3.2.134, R7000 1.0.11.123, R7000P 1.3.2.134, R7850 1.0.5.68, R7900 1.0.4.38, R8000 1.0.4.68, and RS400 1.5.0.68.

8.1
CVSS
10.0%
EPSS (exploit prob.)
95th
EPSS percentile
2021-09-21
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-319

Affected products

VendorProductAffected versions
netgearr6400v2_firmware1.0.4.106
netgearr6400v2all versions
netgearr6700_firmware1.0.2.16
netgearr6700all versions
netgearr6700v3_firmware1.0.4.106
netgearr6700v3all versions
netgearr6900_firmware1.0.2.16
netgearr6900all versions
netgearr6900p_firmware1.3.2.134
netgearr6900pall versions
netgearr7000_firmware1.0.11.123
netgearr7000all versions
netgearr7000p_firmware1.3.2.134
netgearr7000pall versions
netgearr7850_firmware1.0.5.68
netgearr7850all versions
netgearr7900_firmware1.0.4.38
netgearr7900all versions
netgearr8000_firmware1.0.4.68
netgearr8000all versions
netgearrs400_firmware1.5.0.68
netgearrs400all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-40847