PT-2020-10728 · NetGear · Jndr3000+23

Wayne Chin Yick Low

·

Published

2020-04-16

·

Updated

2020-04-23

·

CVE-2019-20753

CVSS v3.1

8.8

High

VectorAC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions NETGEAR DGN2200v1 versions 1.0.0.0 through 1.0.0.57 NETGEAR D8500 versions 1.0.0.0 through 1.0.3.41 NETGEAR D7000v2 versions 1.0.0.0 through 1.0.0.50 NETGEAR D6400 versions 1.0.0.0 through 1.0.0.77 NETGEAR D6220 versions 1.0.0.0 through 1.0.0.43 NETGEAR JNDR3000 versions 1.0.0.0 through 1.0.0.23 NETGEAR R8000 versions 1.0.0.0 through 1.0.4.17 NETGEAR R8500 versions 1.0.0.0 through 1.0.2.121 NETGEAR R8300 versions 1.0.0.0 through 1.0.2.121 NETGEAR R7900 versions 1.0.0.0 through 1.0.2.15 NETGEAR R7000P versions 1.0.0.0 through 1.3.2.33 NETGEAR R7300DST versions 1.0.0.0 through 1.0.0.67 NETGEAR R7100LG versions 1.0.0.0 through 1.0.0.45 NETGEAR R6900P versions 1.0.0.0 through 1.3.2.33 NETGEAR R7000 versions 1.0.0.0 through 1.0.9.27 NETGEAR R6900 versions 1.0.0.0 through 1.0.1.45 NETGEAR R6700 versions 1.0.0.0 through 1.0.1.45 NETGEAR R6400v2 versions 1.0.0.0 through 1.0.2.55 NETGEAR R6400 versions 1.0.0.0 through 1.0.1.41 NETGEAR R6300v2 versions 1.0.0.0 through 1.0.4.27 NETGEAR R6250 versions 1.0.0.0 through 1.0.4.25 NETGEAR WNDR3400v3 versions 1.0.0.0 through 1.0.1.21 NETGEAR WNDR4500v2 versions 1.0.0.0 through 1.0.0.71 NETGEAR WNR3500Lv2 versions 1.0.0.0 through 1.2.0.49
Description The issue is a stack-based buffer overflow that can be exploited by an unauthenticated attacker.
Recommendations Update DGN2200v1 to version 1.0.0.58 or later. Update D8500 to version 1.0.3.42 or later. Update D7000v2 to version 1.0.0.51 or later. Update D6400 to version 1.0.0.78 or later. Update D6220 to version 1.0.0.44 or later. Update JNDR3000 to version 1.0.0.24 or later. Update R8000 to version 1.0.4.18 or later. Update R8500 to version 1.0.2.122 or later. Update R8300 to version 1.0.2.122 or later. Update R7900 to version 1.0.2.16 or later. Update R7000P to version 1.3.2.34 or later. Update R7300DST to version 1.0.0.68 or later. Update R7100LG to version 1.0.0.46 or later. Update R6900P to version 1.3.2.34 or later. Update R7000 to version 1.0.9.28 or later. Update R6900 to version 1.0.1.46 or later. Update R6700 to version 1.0.1.46 or later. Update R6400v2 to version 1.0.2.56 or later. Update R6400 to version 1.0.1.42 or later. Update R6300v2 to version 1.0.4.28 or later. Update R6250 to version 1.0.4.26 or later. Update WNDR3400v3 to version 1.0.1.22 or later. Update WNDR4500v2 to version 1.0.0.72 or later. Update WNR3500Lv2 to version 1.2.0.50 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20753

Affected Products

D6220
D6400
D7000V2
D8500
Dgn2200V1
Jndr3000
R6250
R6300V2
R6400
R6400V2
R6700
R6900
R6900P
R7000
R7000P
R7100Lg
R7300Dst
R7900
R8000
R8300
R8500
Wndr3400V3
Wndr4500V2
Wnr3500Lv2