PT-2020-10728 · NetGear · Jndr3000+23
Wayne Chin Yick Low
·
Published
2020-04-16
·
Updated
2020-04-23
·
CVE-2019-20753
CVSS v3.1
8.8
High
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
NETGEAR DGN2200v1 versions 1.0.0.0 through 1.0.0.57
NETGEAR D8500 versions 1.0.0.0 through 1.0.3.41
NETGEAR D7000v2 versions 1.0.0.0 through 1.0.0.50
NETGEAR D6400 versions 1.0.0.0 through 1.0.0.77
NETGEAR D6220 versions 1.0.0.0 through 1.0.0.43
NETGEAR JNDR3000 versions 1.0.0.0 through 1.0.0.23
NETGEAR R8000 versions 1.0.0.0 through 1.0.4.17
NETGEAR R8500 versions 1.0.0.0 through 1.0.2.121
NETGEAR R8300 versions 1.0.0.0 through 1.0.2.121
NETGEAR R7900 versions 1.0.0.0 through 1.0.2.15
NETGEAR R7000P versions 1.0.0.0 through 1.3.2.33
NETGEAR R7300DST versions 1.0.0.0 through 1.0.0.67
NETGEAR R7100LG versions 1.0.0.0 through 1.0.0.45
NETGEAR R6900P versions 1.0.0.0 through 1.3.2.33
NETGEAR R7000 versions 1.0.0.0 through 1.0.9.27
NETGEAR R6900 versions 1.0.0.0 through 1.0.1.45
NETGEAR R6700 versions 1.0.0.0 through 1.0.1.45
NETGEAR R6400v2 versions 1.0.0.0 through 1.0.2.55
NETGEAR R6400 versions 1.0.0.0 through 1.0.1.41
NETGEAR R6300v2 versions 1.0.0.0 through 1.0.4.27
NETGEAR R6250 versions 1.0.0.0 through 1.0.4.25
NETGEAR WNDR3400v3 versions 1.0.0.0 through 1.0.1.21
NETGEAR WNDR4500v2 versions 1.0.0.0 through 1.0.0.71
NETGEAR WNR3500Lv2 versions 1.0.0.0 through 1.2.0.49
Description
The issue is a stack-based buffer overflow that can be exploited by an unauthenticated attacker.
Recommendations
Update DGN2200v1 to version 1.0.0.58 or later.
Update D8500 to version 1.0.3.42 or later.
Update D7000v2 to version 1.0.0.51 or later.
Update D6400 to version 1.0.0.78 or later.
Update D6220 to version 1.0.0.44 or later.
Update JNDR3000 to version 1.0.0.24 or later.
Update R8000 to version 1.0.4.18 or later.
Update R8500 to version 1.0.2.122 or later.
Update R8300 to version 1.0.2.122 or later.
Update R7900 to version 1.0.2.16 or later.
Update R7000P to version 1.3.2.34 or later.
Update R7300DST to version 1.0.0.68 or later.
Update R7100LG to version 1.0.0.46 or later.
Update R6900P to version 1.3.2.34 or later.
Update R7000 to version 1.0.9.28 or later.
Update R6900 to version 1.0.1.46 or later.
Update R6700 to version 1.0.1.46 or later.
Update R6400v2 to version 1.0.2.56 or later.
Update R6400 to version 1.0.1.42 or later.
Update R6300v2 to version 1.0.4.28 or later.
Update R6250 to version 1.0.4.26 or later.
Update WNDR3400v3 to version 1.0.1.22 or later.
Update WNDR4500v2 to version 1.0.0.72 or later.
Update WNR3500Lv2 to version 1.2.0.50 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D6220
D6400
D7000V2
D8500
Dgn2200V1
Jndr3000
R6250
R6300V2
R6400
R6400V2
R6700
R6900
R6900P
R7000
R7000P
R7100Lg
R7300Dst
R7900
R8000
R8300
R8500
Wndr3400V3
Wndr4500V2
Wnr3500Lv2