PT-2020-10660 · NetGear · R6120+17
Published
2020-04-16
·
Updated
2020-04-21
·
CVE-2019-20685
CVSS v3.1
8.8
High
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
D3600 versions 1.0.0.0 through 1.0.0.74
D6000 versions 1.0.0.0 through 1.0.0.74
D6200 versions 1.0.0.0 through 1.1.00.31
D7000 versions 1.0.0.0 through 1.0.1.67
DM200 versions 1.0.0.0 through 1.0.0.57
JR6150 versions 1.0.0.0 through 1.0.1.17
PR2000 versions 1.0.0.0 through 1.0.0.27
R6020 versions 1.0.0.0 through 1.0.0.37
R6050 versions 1.0.0.0 through 1.0.1.17
R6080 versions 1.0.0.0 through 1.0.0.37
R6120 versions 1.0.0.0 through 1.0.0.45
R6220 versions 1.0.0.0 through 1.1.0.79
R6260 versions 1.0.0.0 through 1.1.0.39
R6700v2 versions 1.0.0.0 through 1.2.0.35
R6800 versions 1.0.0.0 through 1.2.0.35
R6900v2 versions 1.0.0.0 through 1.2.0.35
WNR2020 versions 1.0.0.0 through 1.1.0.61
XR500 versions 1.0.0.0 through 2.3.2.31
Description
The issue is a stack-based buffer overflow that can be exploited by an unauthenticated attacker.
Recommendations
For D3600, update to version 1.0.0.75 or later.
For D6000, update to version 1.0.0.75 or later.
For D6200, update to version 1.1.00.32 or later.
For D7000, update to version 1.0.1.68 or later.
For DM200, update to version 1.0.0.58 or later.
For JR6150, update to version 1.0.1.18 or later.
For PR2000, update to version 1.0.0.28 or later.
For R6020, update to version 1.0.0.38 or later.
For R6050, update to version 1.0.1.18 or later.
For R6080, update to version 1.0.0.38 or later.
For R6120, update to version 1.0.0.46 or later.
For R6220, update to version 1.1.0.80 or later.
For R6260, update to version 1.1.0.40 or later.
For R6700v2, update to version 1.2.0.36 or later.
For R6800, update to version 1.2.0.36 or later.
For R6900v2, update to version 1.2.0.36 or later.
For WNR2020, update to version 1.1.0.62 or later.
For XR500, update to version 2.3.2.32 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D3600
D6000
D6200
D7000
Dm200
Jr6150
Pr2000
R6020
R6050
R6080
R6120
R6220
R6260
R6700V2
R6800
R6900V2
Wnr2020
Xr500