Vulnerability record · CVE-2021-27276 · published 29 March 2021
CVE-2021-27276: NETGEAR ProSAFE NMS path traversal in MibController allows file deletion
Netgear · Prosafe Network Management System
CVE-2021-27276 is a path traversal (CWE-22) in the MibController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker delete arbitrary files. The result is a denial-of-service condition on the management system.
Description
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MibController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12122.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Automated analysis
high priorityCVSS 7.1 with high availability impact and a very high EPSS percentile, though no KEV listing or confirmed exploitation is recorded.
What it is
CVE-2021-27276 is a path traversal (CWE-22) in the MibController class of NETGEAR ProSAFE Network Management System 1.6.0.26. The realName parameter is not validated before being used in file operations, letting an attacker delete arbitrary files. The result is a denial-of-service condition on the management system.
Impact
An attacker can delete arbitrary files on the affected installation, which can render the NMS unavailable and disrupt management of the network devices it controls. Integrity impact is limited and there is no confidentiality impact per the CVSS vector.
Attack surface
Reachable over the network via the MibController's realName parameter. Authentication is nominally required, but the description states the existing authentication mechanism can be bypassed, and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is recorded in the references, which are vendor and ZDI advisories only. EPSS is high (0.72461, 99.4th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Apply the NETGEAR security advisory fix for NMS300 (PSV-2020-0500) or upgrade to a corrected release; no fixed version is stated in this record.
- Restrict network access to the ProSAFE NMS management interface to trusted administrative networks and block it from the internet.
- Enforce strong, unique administrative credentials and review the authentication bypass path noted in the advisory.
- Monitor and back up NMS configuration and data so deleted files can be restored quickly.
- If patching is delayed, isolate the NMS host on a segmented management VLAN.
Detection
- Alert on file deletion or modification events in NMS installation and data directories, especially outside maintenance windows.
- Monitor NMS application and web server logs for requests to MibController endpoints with traversal sequences (../, encoded variants) in the realName parameter.
- Watch for unexpected NMS service crashes, restarts or loss of management visibility that follow suspicious HTTP requests.
- Correlate NMS access logs with authentication events to spot sessions that bypass normal login flows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.netgear.com/000062722/Security-Advisory-for-Denial-of-Service-on-NMS300-PSV-2020-0500 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-359/ | Third Party AdvisoryVDB Entry |
| https://kb.netgear.com/000062722/Security-Advisory-for-Denial-of-Service-on-NMS300-PSV-2020-0500 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-359/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-27276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27276), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.