CVE-2021-34991 is a critical vulnerability affecting NETGEAR R6400v2 1.0.4.106_10.0.80 routers, allowing network-adjacent attackers to execute arbitrary code without authentication. The flaw resides in the UPnP service's handling of the uuid request header, leading to a stack-based buffer overflow. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, granting attackers root-level code execution and full control over the device. While not listed in CISA's KEV catalog, there is some community discussion and media coverage, indicating awareness, but no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.94CPE matchmatch criteria | cpe:2.3:o:netgear:ex3700_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.94CPE matchmatch criteria | cpe:2.3:o:netgear:ex3800_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.66CPE matchmatch criteria | cpe:2.3:o:netgear:ex6120_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.66CPE matchmatch criteria | cpe:2.3:o:netgear:ex6130_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.1.76CPE matchmatch criteria | cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.