ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-27866

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-11355.
8.8
CVSS
6.8
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorAdjacent
ComplexityLow
RequirementsPresent
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21nucleiE: U→P5.2 → 6.8
2026-07-21cve.orginitial, patch: Unavailable5.2

Affected Software
VendorProductVersion
netgearac2100_firmware< 1.2.0.76
netgearac2400_firmware< 1.2.0.76
netgearac2600_firmware< 1.2.0.76
NETGEARMultiple Routersfirmware version 1.2.0.62_1.0.1
netgearr6020_firmware< 1.0.0.48
netgearr6080_firmware< 1.0.0.48
netgearr6120_firmware< 1.0.0.76
netgearr6220_firmware< 1.1.0.104
netgearr6230_firmware< 1.1.0.104
netgearr6260_firmware< 1.1.0.78
netgearr6330_firmware< 1.1.0.78
netgearr6350_firmware< 1.1.0.78
netgearr6700_firmware< 1.2.0.76
netgearr6800_firmware< 1.2.0.76
netgearr6850_firmware< 1.1.0.78
netgearr6900_firmware< 1.2.0.76
netgearr7200_firmware< 1.2.0.76
netgearr7350_firmware< 1.2.0.76
netgearr7400_firmware< 1.2.0.76
netgearr7450_firmware< 1.2.0.76
Published: 2021-02-11