← Vulnerability feed

Vulnerability record · CVE-2021-27276 · published 29 March 2021

CVE-2021-27276: NETGEAR ProSAFE NMS path traversal in MibController allows file deletion

Netgear · Prosafe Network Management System

CVE-2021-27276 is a path traversal (CWE-22) in the MibController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker delete arbitrary files. The result is a denial-of-service condition on the management system.

7.1 CVSS 3.1 High EPSS 72% · top 0.6% CWE-22 · Path traversal
7.1CVSS 3.1 base score, v2 5.5
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MibController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12122.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.1 with high availability impact and a very high EPSS percentile, though no KEV listing or confirmed exploitation is recorded.

What it is

CVE-2021-27276 is a path traversal (CWE-22) in the MibController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker delete arbitrary files. The result is a denial-of-service condition on the management system.

Impact

An attacker can delete arbitrary files on the affected installation, which can render the NMS unavailable and disrupt management of the network devices it controls. Integrity impact is limited and there is no confidentiality impact per the CVSS vector.

Attack surface

Reachable over the network via the MibController's realName parameter. Authentication is nominally required, but the description states the existing authentication mechanism can be bypassed, and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware usage is recorded in the references, which are vendor and ZDI advisories only. EPSS is high (0.72461, 99.4th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.

What to do

  • Apply the NETGEAR security advisory fix for NMS300 (PSV-2020-0500) or upgrade to a corrected release; no fixed version is stated in this record.
  • Restrict network access to the ProSAFE NMS management interface to trusted administrative networks and block it from the internet.
  • Enforce strong, unique administrative credentials and review the authentication bypass path noted in the advisory.
  • Monitor and back up NMS configuration and data so deleted files can be restored quickly.
  • If patching is delayed, isolate the NMS host on a segmented management VLAN.

Detection

  • Alert on file deletion or modification events in NMS installation and data directories, especially outside maintenance windows.
  • Monitor NMS application and web server logs for requests to MibController endpoints with traversal sequences (../, encoded variants) in the realName parameter.
  • Watch for unexpected NMS service crashes, restarts or loss of management visibility that follow suspicious HTTP requests.
  • Correlate NMS access logs with authentication events to spot sessions that bypass normal login flows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38096NETGEAR ProSAFE NMS MyHandlerInterceptor authentication bypassThe NETGEAR ProSAFE Network Management System contains an authentication bypass in the MyHandlerInterceptor class caused by improper implementation o…EPSS 82%analysed9.8CVE-2023-49693Netgear prosafe network management system missing authentication for critical function vulnerabilityNETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticate…EPSS 1.2%9.8CVE-2021-27274Netgear prosafe network management system unrestricted file upload vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…EPSS 8.2%9.6CVE-2023-50231NETGEAR ProSAFE NMS saveNodeLabel stored XSS privilege escalationThe saveNodeLabel method in NETGEAR ProSAFE Network Management System fails to validate user-supplied data, allowing injection of arbitrary script. B…EPSS 53%analysed8.8CVE-2024-6813Netgear prosafe network management system sql injection vulnerabilityNETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers…EPSS 1.8%8.8CVE-2024-6814Netgear prosafe network management system sql injection vulnerabilityNETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…EPSS 2.1%8.8CVE-2024-5505NETGEAR ProSAFE NMS UpLoadServlet path traversal leads to RCEThe UpLoadServlet class in NETGEAR ProSAFE Network Management System fails to validate a user-supplied path before using it in file operations, allow…EPSS 47%analysed8.8CVE-2024-5247Netgear prosafe network management system unrestricted file upload vulnerabilityNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2021-27276), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.