PT-2020-10687 · NetGear · R7900P+24

Wayne Low

·

Published

2020-04-16

·

Updated

2020-04-23

·

CVE-2019-20712

CVSS v3.1

6.8

Medium

VectorAC:L/AV:A/A:H/C:H/I:H/PR:H/S:U/UI:N
Name of the Vulnerable Software and Affected Versions NETGEAR D6220 versions 1.0.0.0 through 1.0.0.51 NETGEAR D6400 versions 1.0.0.0 through 1.0.0.85 NETGEAR D7000v2 versions 1.0.0.0 through 1.0.0.52 NETGEAR D8500 versions 1.0.0.0 through 1.0.3.43 NETGEAR DGN2200v4 versions 1.0.0.0 through 1.0.0.109 NETGEAR DGND2200Bv4 versions 1.0.0.0 through 1.0.0.108 NETGEAR R6250 versions 1.0.0.0 through 1.0.4.33 NETGEAR R6300v2 versions 1.0.0.0 through 1.0.4.31 NETGEAR R6400 versions 1.0.0.0 through 1.0.1.45 NETGEAR R6400v2 versions 1.0.0.0 through 1.0.2.61 NETGEAR R6700 versions 1.0.0.0 through 1.0.2.5 NETGEAR R6900 versions 1.0.0.0 through 1.0.2.3 NETGEAR R6900P versions 1.0.0.0 through 1.3.1.63 NETGEAR R7000 versions 1.0.0.0 through 1.0.9.59 NETGEAR R7000P versions 1.0.0.0 through 1.3.1.63 NETGEAR R7100LG versions 1.0.0.0 through 1.0.0.51 NETGEAR R7300DST versions 1.0.0.0 through 1.0.0.69 NETGEAR R7900 versions 1.0.0.0 through 1.0.3.7 NETGEAR R7900P versions 1.0.0.0 through 1.4.1.29 NETGEAR R8000 versions 1.0.0.0 through 1.0.4.27 NETGEAR R8000P versions 1.0.0.0 through 1.4.1.29 NETGEAR R8300 versions 1.0.0.0 through 1.0.2.127 NETGEAR R8500 versions 1.0.0.0 through 1.0.2.127 NETGEAR WNDR3400v3 versions 1.0.0.0 through 1.0.1.23 NETGEAR WNR3500Lv2 versions 1.0.0.0 through 1.2.0.55
Description The issue is a buffer overflow that can be triggered by an authenticated user.
Recommendations For NETGEAR D6220 version 1.0.0.51 and earlier, update to version 1.0.0.52 or later. For NETGEAR D6400 version 1.0.0.85 and earlier, update to version 1.0.0.86 or later. For NETGEAR D7000v2 version 1.0.0.52 and earlier, update to version 1.0.0.53 or later. For NETGEAR D8500 version 1.0.3.43 and earlier, update to version 1.0.3.44 or later. For NETGEAR DGN2200v4 version 1.0.0.109 and earlier, update to version 1.0.0.110 or later. For NETGEAR DGND2200Bv4 version 1.0.0.108 and earlier, update to version 1.0.0.109 or later. For NETGEAR R6250 version 1.0.4.33 and earlier, update to version 1.0.4.34 or later. For NETGEAR R6300v2 version 1.0.4.31 and earlier, update to version 1.0.4.32 or later. For NETGEAR R6400 version 1.0.1.45 and earlier, update to version 1.0.1.46 or later. For NETGEAR R6400v2 version 1.0.2.61 and earlier, update to version 1.0.2.62 or later. For NETGEAR R6700 version 1.0.2.5 and earlier, update to version 1.0.2.6 or later. For NETGEAR R6900 version 1.0.2.3 and earlier, update to version 1.0.2.4 or later. For NETGEAR R6900P version 1.3.1.63 and earlier, update to version 1.3.1.64 or later. For NETGEAR R7000 version 1.0.9.59 and earlier, update to version 1.0.9.60 or later. For NETGEAR R7000P version 1.3.1.63 and earlier, update to version 1.3.1.64 or later. For NETGEAR R7100LG version 1.0.0.51 and earlier, update to version 1.0.0.52 or later. For NETGEAR R7300DST version 1.0.0.69 and earlier, update to version 1.0.0.70 or later. For NETGEAR R7900 version 1.0.3.7 and earlier, update to version 1.0.3.8 or later. For NETGEAR R7900P version 1.4.1.29 and earlier, update to version 1.4.1.30 or later. For NETGEAR R8000 version 1.0.4.27 and earlier, update to version 1.0.4.28 or later. For NETGEAR R8000P version 1.4.1.29 and earlier, update to version 1.4.1.30 or later. For NETGEAR R8300 version 1.0.2.127 and earlier, update to version 1.0.2.128 or later. For NETGEAR R8500 version 1.0.2.127 and earlier, update to version 1.0.2.128 or later. For NETGEAR WNDR3400v3 version 1.0.1.23 and earlier, update to version 1.0.1.24 or later. For NETGEAR WNR3500Lv2 version 1.2.0.55 and earlier, update to version 1.2.0.56 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20712

Affected Products

D6220
D6400
D7000V2
D8500
Dgn2200V4
Dgnd2200Bv4
R6250
R6300V2
R6400
R6400V2
R6700
R6900
R6900P
R7000
R7000P
R7100Lg
R7300Dst
R7900
R7900P
R8000
R8000P
R8300
R8500
Wndr3400V3
Wnr3500Lv2