.. / CVE-2020-27866

Exploit for NETGEAR - Authentication Bypass (CVE-2020-27866)

Description:

NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers are vulnerable to authentication bypass vulnerabilities which could allow network-adjacent attackers to bypass authentication on affected installations.

Nuclei Template

View the template here CVE-2020-27866.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-27866.yaml
Copy

References:

https://kb.netgear.com/000062641/Security-Advisory-for-Password-Recovery-Vulnerabilities-on-Some-Routers
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27866
https://wzt.ac.cn/2021/01/13/AC2400_vuln/
https://nvd.nist.gov/vuln/detail/CVE-2020-27866
https://www.zerodayinitiative.com/advisories/ZDI-20-1451/