CVE-2021-41314

HIGHCVSS 8.8/10EPSS 13.62%

Last modified

CVE-2021-41314 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2" string). This leads to admin session crafting and therefore gaining full web UI admin privileges by an unauthenticated attacker. EPSS estimates a 13.62% chance of exploitation in the next 30 days.

Description

Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2" string). This leads to admin session crafting and therefore gaining full web UI admin privileges by an unauthenticated attacker. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
13.62%

96.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearGc108p Firmware< 1.0.8.2
NetgearGc108pp Firmware< 1.0.8.2
NetgearGs108t Firmware< 7.0.7.2
NetgearGs110tpp Firmware< 7.0.7.2
NetgearGs110tp Firmware< 7.0.7.2
NetgearGs110tup Firmware< 1.0.5.3
NetgearGs308t Firmware< 1.0.3.2
NetgearGs310tp Firmware< 1.0.3.2
NetgearGs710tup Firmware< 1.0.5.3
NetgearGs716tp Firmware< 1.0.4.2
NetgearGs716tpp Firmware< 1.0.4.2
NetgearGs724tpp Firmware< 2.0.6.3
NetgearGs724tp Firmware< 2.0.6.3
NetgearGs728tpp Firmware< 2.0.6.3
NetgearGs728tp Firmware< 2.0.6.3
NetgearGs750e Firmware< 1.0.1.10
NetgearGs752tpp Firmware< 6.0.8.2
NetgearGs752tp Firmware< 6.0.8.2
NetgearMs510txm Firmware< 1.0.4.2
NetgearMs510txup Firmware< 1.0.4.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-41314?
Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2" string). This leads to admin session crafting and therefore gaining full web UI admin privileges by an unauthenticated attacker. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.
How severe is CVE-2021-41314?
CVE-2021-41314 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 13.62% probability of exploitation in the next 30 days.
How do I fix CVE-2021-41314?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-41314?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST