PT-2020-10660 · NetGear · R6120+17

Published

2020-04-16

·

Updated

2020-04-21

·

CVE-2019-20685

CVSS v3.1

8.8

High

VectorAC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions D3600 versions 1.0.0.0 through 1.0.0.74 D6000 versions 1.0.0.0 through 1.0.0.74 D6200 versions 1.0.0.0 through 1.1.00.31 D7000 versions 1.0.0.0 through 1.0.1.67 DM200 versions 1.0.0.0 through 1.0.0.57 JR6150 versions 1.0.0.0 through 1.0.1.17 PR2000 versions 1.0.0.0 through 1.0.0.27 R6020 versions 1.0.0.0 through 1.0.0.37 R6050 versions 1.0.0.0 through 1.0.1.17 R6080 versions 1.0.0.0 through 1.0.0.37 R6120 versions 1.0.0.0 through 1.0.0.45 R6220 versions 1.0.0.0 through 1.1.0.79 R6260 versions 1.0.0.0 through 1.1.0.39 R6700v2 versions 1.0.0.0 through 1.2.0.35 R6800 versions 1.0.0.0 through 1.2.0.35 R6900v2 versions 1.0.0.0 through 1.2.0.35 WNR2020 versions 1.0.0.0 through 1.1.0.61 XR500 versions 1.0.0.0 through 2.3.2.31
Description The issue is a stack-based buffer overflow that can be exploited by an unauthenticated attacker.
Recommendations For D3600, update to version 1.0.0.75 or later. For D6000, update to version 1.0.0.75 or later. For D6200, update to version 1.1.00.32 or later. For D7000, update to version 1.0.1.68 or later. For DM200, update to version 1.0.0.58 or later. For JR6150, update to version 1.0.1.18 or later. For PR2000, update to version 1.0.0.28 or later. For R6020, update to version 1.0.0.38 or later. For R6050, update to version 1.0.1.18 or later. For R6080, update to version 1.0.0.38 or later. For R6120, update to version 1.0.0.46 or later. For R6220, update to version 1.1.0.80 or later. For R6260, update to version 1.1.0.40 or later. For R6700v2, update to version 1.2.0.36 or later. For R6800, update to version 1.2.0.36 or later. For R6900v2, update to version 1.2.0.36 or later. For WNR2020, update to version 1.1.0.62 or later. For XR500, update to version 2.3.2.32 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20685

Affected Products

D3600
D6000
D6200
D7000
Dm200
Jr6150
Pr2000
R6020
R6050
R6080
R6120
R6220
R6260
R6700V2
R6800
R6900V2
Wnr2020
Xr500