PT-2020-16555 · NetGear · Xr500+21
Aircut
·
Published
2020-10-09
·
Updated
2020-10-16
·
CVE-2020-26913
CVSS v3.1
6.8
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR D6100 versions prior to 1.0.0.63
NETGEAR R7800 versions prior to 1.0.2.60
NETGEAR R8900 versions prior to 1.0.4.26
NETGEAR R9000 versions prior to 1.0.4.26
NETGEAR RBK20 versions prior to 2.3.0.28
NETGEAR RBR20 versions prior to 2.3.0.28
NETGEAR RBS20 versions prior to 2.3.0.28
NETGEAR RBK50 versions prior to 2.3.0.32
NETGEAR RBR50 versions prior to 2.3.0.32
NETGEAR RBS50 versions prior to 2.3.0.32
NETGEAR RBK40 versions prior to 2.3.0.28
NETGEAR RBR40 versions prior to 2.3.0.28
NETGEAR RBS40 versions prior to 2.3.0.28
NETGEAR SRK60 versions prior to 2.2.2.20
NETGEAR SRR60 versions prior to 2.2.2.20
NETGEAR SRS60 versions prior to 2.2.2.20
NETGEAR WN3000RPv2 versions prior to 1.0.0.78
NETGEAR WNDR4300v2 versions prior to 1.0.0.58
NETGEAR WNDR4500v3 versions prior to 1.0.0.58
NETGEAR WNR2000v5 versions prior to 1.0.0.70
NETGEAR XR450 versions prior to 2.3.2.40
NETGEAR XR500 versions prior to 2.3.2.40
Description
A stack-based buffer overflow issue affects certain NETGEAR devices, allowing an authenticated user to potentially exploit this issue.
Recommendations
For NETGEAR D6100 version prior to 1.0.0.63, update to version 1.0.0.63 or later.
For NETGEAR R7800 version prior to 1.0.2.60, update to version 1.0.2.60 or later.
For NETGEAR R8900 version prior to 1.0.4.26, update to version 1.0.4.26 or later.
For NETGEAR R9000 version prior to 1.0.4.26, update to version 1.0.4.26 or later.
For NETGEAR RBK20 version prior to 2.3.0.28, update to version 2.3.0.28 or later.
For NETGEAR RBR20 version prior to 2.3.0.28, update to version 2.3.0.28 or later.
For NETGEAR RBS20 version prior to 2.3.0.28, update to version 2.3.0.28 or later.
For NETGEAR RBK50 version prior to 2.3.0.32, update to version 2.3.0.32 or later.
For NETGEAR RBR50 version prior to 2.3.0.32, update to version 2.3.0.32 or later.
For NETGEAR RBS50 version prior to 2.3.0.32, update to version 2.3.0.32 or later.
For NETGEAR RBK40 version prior to 2.3.0.28, update to version 2.3.0.28 or later.
For NETGEAR RBR40 version prior to 2.3.0.28, update to version 2.3.0.28 or later.
For NETGEAR RBS40 version prior to 2.3.0.28, update to version 2.3.0.28 or later.
For NETGEAR SRK60 version prior to 2.2.2.20, update to version 2.2.2.20 or later.
For NETGEAR SRR60 version prior to 2.2.2.20, update to version 2.2.2.20 or later.
For NETGEAR SRS60 version prior to 2.2.2.20, update to version 2.2.2.20 or later.
For NETGEAR WN3000RPv2 version prior to 1.0.0.78, update to version 1.0.0.78 or later.
For NETGEAR WNDR4300v2 version prior to 1.0.0.58, update to version 1.0.0.58 or later.
For NETGEAR WNDR4500v3 version prior to 1.0.0.58, update to version 1.0.0.58 or later.
For NETGEAR WNR2000v5 version prior to 1.0.0.70, update to version 1.0.0.70 or later.
For NETGEAR XR450 version prior to 2.3.2.40, update to version 2.3.2.40 or later.
For NETGEAR XR500 version prior to 2.3.2.40, update to version 2.3.2.40 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D6100
R7800
R8900
R9000
Rbk20
Rbk40
Rbk50
Rbr20
Rbr40
Rbr50
Rbs20
Rbs40
Rbs50
Srk60
Srr60
Srs60
Wn3000Rpv2
Wndr4300V2
Wndr4500V3
Wnr2000V5
Xr450
Xr500