Vulnerability record · CVE-2021-27275 · published 29 March 2021
CVE-2021-27275: NETGEAR ProSAFE NMS path traversal in ConfigFileController
Netgear · Prosafe Network Management System
CVE-2021-27275 is a path traversal (CWE-22) in the ConfigFileController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker read sensitive files or delete arbitrary files. Authentication is required but the existing authentication mechanism can be bypassed, so the flaw is reachable by remote attackers.
Description
This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ConfigFileController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose sensitive information or to create a denial-of-service condition on the system. Was ZDI-CAN-12125.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Automated analysis
high priorityCVSS 8.3 with high confidentiality and availability impact plus a very high EPSS score, though no KEV listing or confirmed public exploit.
What it is
CVE-2021-27275 is a path traversal (CWE-22) in the ConfigFileController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker read sensitive files or delete arbitrary files. Authentication is required but the existing authentication mechanism can be bypassed, so the flaw is reachable by remote attackers.
Impact
An attacker can disclose sensitive information from the host and delete arbitrary files, which can also produce a denial-of-service condition on the NMS installation.
Attack surface
Reached remotely over the network via the ConfigFileController endpoint and its realName parameter. Authentication is nominally required, but the record states the authentication mechanism can be bypassed, and no user interaction is needed per the CVSS vector.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is high (0.73318, 99.4th percentile), and references are only vendor and Zero Day Initiative advisories, so no public exploit code is confirmed by this record.
What to do
- Apply the NETGEAR security advisory fix for NMS300 (PSV-2020-0561) and upgrade ProSAFE NMS to the patched release.
- Restrict network access to the NMS management interface to trusted administrative networks only.
- Do not expose the NMS web interface to the internet or untrusted segments.
- Audit and rotate credentials for the NMS and any secrets stored on the host, given the file disclosure risk.
- Monitor for unexpected deletion or modification of files on the NMS host and keep offline backups.
Detection
- Review NMS and web server logs for requests to ConfigFileController with traversal sequences in the realName parameter.
- Alert on file access or deletion events on the NMS host involving paths outside expected configuration directories.
- Monitor for authentication bypass attempts or anomalous sessions preceding file operations on the NMS.
- Watch for service outages or missing configuration files on the NMS host that could indicate destructive traversal.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.netgear.com/000062687/Security-Advisory-for-Denial-of-Service-on-NMS300-PSV-2020-0561 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-358/ | Third Party AdvisoryVDB Entry |
| https://kb.netgear.com/000062687/Security-Advisory-for-Denial-of-Service-on-NMS300-PSV-2020-0561 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-358/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-27275 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27275), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.