PT-2020-10659 · NetGear · Xr500+16

Published

2020-04-16

·

Updated

2020-04-21

·

CVE-2019-20684

CVSS v3.1

8.8

High

VectorAC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions NETGEAR D3600 versions prior to 1.0.0.75 NETGEAR D6000 versions prior to 1.0.0.75 NETGEAR D6200 versions prior to 1.1.00.32 NETGEAR D7000 versions prior to 1.0.1.68 NETGEAR JR6150 versions prior to 1.0.1.18 NETGEAR PR2000 versions prior to 1.0.0.28 NETGEAR R6020 versions prior to 1.0.0.38 NETGEAR R6050 versions prior to 1.0.1.18 NETGEAR R6080 versions prior to 1.0.0.38 NETGEAR R6120 versions prior to 1.0.0.46 NETGEAR R6220 versions prior to 1.1.0.80 NETGEAR R6260 versions prior to 1.1.0.40 NETGEAR R6700v2 versions prior to 1.2.0.36 NETGEAR R6800 versions prior to 1.2.0.36 NETGEAR R6900v2 versions prior to 1.2.0.36 NETGEAR WNR2020 versions prior to 1.1.0.62 NETGEAR XR500 versions prior to 2.3.2.32
Description The issue is a stack-based buffer overflow that can be exploited by an unauthenticated attacker.
Recommendations For NETGEAR D3600, update to version 1.0.0.75 or later. For NETGEAR D6000, update to version 1.0.0.75 or later. For NETGEAR D6200, update to version 1.1.00.32 or later. For NETGEAR D7000, update to version 1.0.1.68 or later. For NETGEAR JR6150, update to version 1.0.1.18 or later. For NETGEAR PR2000, update to version 1.0.0.28 or later. For NETGEAR R6020, update to version 1.0.0.38 or later. For NETGEAR R6050, update to version 1.0.1.18 or later. For NETGEAR R6080, update to version 1.0.0.38 or later. For NETGEAR R6120, update to version 1.0.0.46 or later. For NETGEAR R6220, update to version 1.1.0.80 or later. For NETGEAR R6260, update to version 1.1.0.40 or later. For NETGEAR R6700v2, update to version 1.2.0.36 or later. For NETGEAR R6800, update to version 1.2.0.36 or later. For NETGEAR R6900v2, update to version 1.2.0.36 or later. For NETGEAR WNR2020, update to version 1.1.0.62 or later. For NETGEAR XR500, update to version 2.3.2.32 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20684

Affected Products

D3600
D6000
D6200
D7000
Jr6150
Pr2000
R6020
R6050
R6080
R6120
R6220
R6260
R6700V2
R6800
R6900V2
Wnr2020
Xr500