CVE-2021-27252 is a critical arbitrary code execution vulnerability affecting NETGEAR R7800 firmware version 1.0.2.76. The flaw stems from improper validation of a user-supplied string within the vendor_specific DHCP opcode, leading to a system call injection. With a CVSS score of 8.8 (High), this vulnerability allows unauthenticated, network-adjacent attackers to execute code as root with low attack complexity. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for complete compromise of affected devices is significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.10.0.5CPE matchmatch criteria | cpe:2.3:o:netgear:br200_firmware:*:*:*:*:*:*:*:* | ||
< 5.10.0.5CPE matchmatch criteria | cpe:2.3:o:netgear:br500_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.60CPE matchmatch criteria | cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.98CPE matchmatch criteria | cpe:2.3:o:netgear:ex6100v2_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.98CPE matchmatch criteria | cpe:2.3:o:netgear:ex6150_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.