High severity8.8NVD Advisory· Published Feb 12, 2021· Updated Jun 17, 2026
CVE-2020-27861
CVE-2020-27861
Description
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11076.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
41- cpe:2.3:o:netgear:rbk20_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk20_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
- cpe:2.3:o:netgear:rbk22_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk22_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
- cpe:2.3:o:netgear:rbk23_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk23_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
- cpe:2.3:o:netgear:rbk40_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk40_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
- cpe:2.3:o:netgear:rbk43_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk43_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
- cpe:2.3:o:netgear:rbk43s_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk43s_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
- cpe:2.3:o:netgear:rbk44_router_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.36
- cpe:2.3:o:netgear:rbk44_satellite_firmware:*:*:*:*:*:*:*:*Range: <2.6.1.38
Patches
Vulnerability mechanics
References
2- kb.netgear.com/000062507/Security-Advisory-for-Unauthenticated-Command-Injection-Vulnerability-on-Some-Extenders-and-Orbi-WiFi-SystemsnvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-20-1430/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.