CVE-2021-34982

HIGH
Published May 7, 2024 Modified Aug 14, 2025 CWE-121 CWE-787

Description

NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. When parsing the strings file, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-13709.

Is your site exposed to CVE-2021-34982?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.8
HIGH
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-121 CWE-121
CWE-787 Out-of-bounds Write

Affected Products

Vendor Product
netgear dc112a_firmware
netgear dc112a
netgear ex3700_firmware
netgear ex3700
netgear ex3800_firmware
netgear ex3800
netgear ex6120_firmware
netgear ex6120
netgear ex6130_firmware
netgear ex6130
netgear ex7000_firmware
netgear ex7000
netgear ex7500_firmware
netgear ex7500
netgear mr60_firmware
netgear mr60
netgear mr80_firmware
netgear mr80
netgear ms60_firmware
netgear ms60
netgear ms80_firmware
netgear ms80
netgear lax20_firmware
netgear lax20
netgear r6400_firmware
netgear r6400
netgear r6400v2_firmware
netgear r6400v2
netgear r6700v3_firmware
netgear r6700v3
netgear r6900p_firmware
netgear r6900p
netgear r7000_firmware
netgear r7000
netgear r7000p_firmware
netgear r7000p
netgear r7100lg_firmware
netgear r7100lg
netgear r7850_firmware
netgear r7850
netgear r7900p_firmware
netgear r7900p
netgear r7960p_firmware
netgear r7960p
netgear r8000_firmware
netgear r8000
netgear r8000p_firmware
netgear r8000p
netgear r8300_firmware
netgear r8300
netgear r8500_firmware
netgear r8500
netgear rax15_firmware
netgear rax15
netgear rax20_firmware
netgear rax20
netgear rax200_firmware
netgear rax200
netgear rax35v2_firmware
netgear rax35v2
netgear rax38v2_firmware
netgear rax38v2
netgear rax40v2_firmware
netgear rax40v2
netgear rax42_firmware
netgear rax42
netgear rax43_firmware
netgear rax43
netgear rax45_firmware
netgear rax45
netgear rax48_firmware
netgear rax48
netgear rax50_firmware
netgear rax50
netgear rax50s_firmware
netgear rax50s
netgear rax75_firmware
netgear rax75
netgear rax80_firmware
netgear rax80
netgear raxe450_firmware
netgear raxe450
netgear raxe500_firmware
netgear raxe500
netgear rs400_firmware
netgear rs400
netgear wndr3400v3_firmware
netgear wndr3400v3
netgear wnr3500lv2_firmware
netgear wnr3500lv2
netgear xr1000_firmware
netgear xr1000
netgear xr300_firmware
netgear xr300
netgear d6220_firmware
netgear d6220
netgear d6400_firmware
netgear d6400
netgear d7000v2_firmware
netgear d7000v2
netgear dgn2200v4_firmware
netgear dgn2200v4
netgear v6510-1fxaus_firmware
netgear v6510-1fxaus

References

Frequently Asked Questions

What is CVE-2021-34982? +
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. When parsing the strings file, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-13709. It has a CVSS v3.1 base score of 8.8 (HIGH).
How severe is CVE-2021-34982? +
CVE-2021-34982 has a CVSS v3.1 score of 8.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2021-34982? +
CVE-2021-34982 affects products from netgear, specifically: d6220, d6220_firmware, d6400, d6400_firmware, d7000v2, d7000v2_firmware, dc112a, dc112a_firmware, dgn2200v4, dgn2200v4_firmware, ex3700, ex3700_firmware, ex3800, ex3800_firmware, ex6120, ex6120_firmware, ex6130, ex6130_firmware, ex7000, ex7000_firmware, ex7500, ex7500_firmware, lax20, lax20_firmware, mr60, mr60_firmware, mr80, mr80_firmware, ms60, ms60_firmware, ms80, ms80_firmware, r6400, r6400_firmware, r6400v2, r6400v2_firmware, r6700v3, r6700v3_firmware, r6900p, r6900p_firmware, r7000, r7000_firmware, r7000p, r7000p_firmware, r7100lg, r7100lg_firmware, r7850, r7850_firmware, r7900p, r7900p_firmware, r7960p, r7960p_firmware, r8000, r8000_firmware, r8000p, r8000p_firmware, r8300, r8300_firmware, r8500, r8500_firmware, rax15, rax15_firmware, rax20, rax200, rax200_firmware, rax20_firmware, rax35v2, rax35v2_firmware, rax38v2, rax38v2_firmware, rax40v2, rax40v2_firmware, rax42, rax42_firmware, rax43, rax43_firmware, rax45, rax45_firmware, rax48, rax48_firmware, rax50, rax50_firmware, rax50s, rax50s_firmware, rax75, rax75_firmware, rax80, rax80_firmware, raxe450, raxe450_firmware, raxe500, raxe500_firmware, rs400, rs400_firmware, v6510-1fxaus, v6510-1fxaus_firmware, wndr3400v3, wndr3400v3_firmware, wnr3500lv2, wnr3500lv2_firmware, xr1000, xr1000_firmware, xr300, xr300_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2021-34982? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2021-34982 — free, no signup required.