← Vulnerability feed

Vulnerability record · CVE-2021-27275 · published 29 March 2021

CVE-2021-27275: NETGEAR ProSAFE NMS path traversal in ConfigFileController

Netgear · Prosafe Network Management System

CVE-2021-27275 is a path traversal (CWE-22) in the ConfigFileController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker read sensitive files or delete arbitrary files. Authentication is required but the existing authentication mechanism can be bypassed, so the flaw is reachable by remote attackers.

8.3 CVSS 3.1 High EPSS 73% · top 0.6% CWE-22 · Path traversal
8.3CVSS 3.1 base score, v2 6.5
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ConfigFileController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose sensitive information or to create a denial-of-service condition on the system. Was ZDI-CAN-12125.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.3 with high confidentiality and availability impact plus a very high EPSS score, though no KEV listing or confirmed public exploit.

What it is

CVE-2021-27275 is a path traversal (CWE-22) in the ConfigFileController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker read sensitive files or delete arbitrary files. Authentication is required but the existing authentication mechanism can be bypassed, so the flaw is reachable by remote attackers.

Impact

An attacker can disclose sensitive information from the host and delete arbitrary files, which can also produce a denial-of-service condition on the NMS installation.

Attack surface

Reached remotely over the network via the ConfigFileController endpoint and its realName parameter. Authentication is nominally required, but the record states the authentication mechanism can be bypassed, and no user interaction is needed per the CVSS vector.

Exploitation

Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.73318, 99.4th percentile), and references are only vendor and Zero Day Initiative advisories, so no public exploit code is confirmed by this record.

What to do

  • Apply the NETGEAR security advisory fix for NMS300 (PSV-2020-0561) and upgrade ProSAFE NMS to the patched release.
  • Restrict network access to the NMS management interface to trusted administrative networks only.
  • Do not expose the NMS web interface to the internet or untrusted segments.
  • Audit and rotate credentials for the NMS and any secrets stored on the host, given the file disclosure risk.
  • Monitor for unexpected deletion or modification of files on the NMS host and keep offline backups.

Detection

  • Review NMS and web server logs for requests to ConfigFileController with traversal sequences in the realName parameter.
  • Alert on file access or deletion events on the NMS host involving paths outside expected configuration directories.
  • Monitor for authentication bypass attempts or anomalous sessions preceding file operations on the NMS.
  • Watch for service outages or missing configuration files on the NMS host that could indicate destructive traversal.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27275 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38096NETGEAR ProSAFE NMS MyHandlerInterceptor authentication bypassThe NETGEAR ProSAFE Network Management System contains an authentication bypass in the MyHandlerInterceptor class caused by improper implementation o…EPSS 82%analysed9.8CVE-2023-49693Netgear prosafe network management system missing authentication for critical function vulnerabilityNETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticate…EPSS 1.2%9.8CVE-2021-27274Netgear prosafe network management system unrestricted file upload vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…EPSS 8.2%9.6CVE-2023-50231NETGEAR ProSAFE NMS saveNodeLabel stored XSS privilege escalationThe saveNodeLabel method in NETGEAR ProSAFE Network Management System fails to validate user-supplied data, allowing injection of arbitrary script. B…EPSS 53%analysed8.8CVE-2024-6813Netgear prosafe network management system sql injection vulnerabilityNETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers…EPSS 1.8%8.8CVE-2024-6814Netgear prosafe network management system sql injection vulnerabilityNETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…EPSS 2.1%8.8CVE-2024-5505NETGEAR ProSAFE NMS UpLoadServlet path traversal leads to RCEThe UpLoadServlet class in NETGEAR ProSAFE Network Management System fails to validate a user-supplied path before using it in file operations, allow…EPSS 47%analysed8.8CVE-2024-5247Netgear prosafe network management system unrestricted file upload vulnerabilityNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2021-27275), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.