PT-2021-5927 · NetGear · Netgear R7450+7

Published

2021-09-25

·

Updated

2022-01-05

·

CVE-2021-45573

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R6260 versions prior to 1.1.0.76 NETGEAR R6800 versions prior to 1.2.0.62 NETGEAR R6700v2 versions prior to 1.2.0.62 NETGEAR R6900v2 versions prior to 1.2.0.62 NETGEAR R7450 versions prior to 1.2.0.62 NETGEAR AC2100 versions prior to 1.2.0.62 NETGEAR AC2400 versions prior to 1.2.0.62 NETGEAR AC2600 versions prior to 1.2.0.62
Description The issue is related to a stack-based buffer overflow that can be exploited by an unauthenticated attacker, allowing remote execution of arbitrary commands. This is due to a data recording issue beyond the buffer boundaries in the software of NETGEAR Wi-Fi routers.
Recommendations For R6260 version prior to 1.1.0.76, update to version 1.1.0.76 or later. For R6800 version prior to 1.2.0.62, update to version 1.2.0.62 or later. For R6700v2 version prior to 1.2.0.62, update to version 1.2.0.62 or later. For R6900v2 version prior to 1.2.0.62, update to version 1.2.0.62 or later. For R7450 version prior to 1.2.0.62, update to version 1.2.0.62 or later. For AC2100 version prior to 1.2.0.62, update to version 1.2.0.62 or later. For AC2400 version prior to 1.2.0.62, update to version 1.2.0.62 or later. For AC2600 version prior to 1.2.0.62, update to version 1.2.0.62 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00442
CVE-2021-45573

Affected Products

Netgear Ac2100
Netgear Ac2400
Netgear Ac2600
Netgear R6260
Netgear R6700V2
Netgear R6800
Netgear R6900V2
Netgear R7450