PT-2021-5927 · NetGear · Netgear R7450+7
Published
2021-09-25
·
Updated
2022-01-05
·
CVE-2021-45573
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR R6260 versions prior to 1.1.0.76
NETGEAR R6800 versions prior to 1.2.0.62
NETGEAR R6700v2 versions prior to 1.2.0.62
NETGEAR R6900v2 versions prior to 1.2.0.62
NETGEAR R7450 versions prior to 1.2.0.62
NETGEAR AC2100 versions prior to 1.2.0.62
NETGEAR AC2400 versions prior to 1.2.0.62
NETGEAR AC2600 versions prior to 1.2.0.62
Description
The issue is related to a stack-based buffer overflow that can be exploited by an unauthenticated attacker, allowing remote execution of arbitrary commands. This is due to a data recording issue beyond the buffer boundaries in the software of NETGEAR Wi-Fi routers.
Recommendations
For R6260 version prior to 1.1.0.76, update to version 1.1.0.76 or later.
For R6800 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For R6700v2 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For R6900v2 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For R7450 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For AC2100 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For AC2400 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
For AC2600 version prior to 1.2.0.62, update to version 1.2.0.62 or later.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Ac2100
Netgear Ac2400
Netgear Ac2600
Netgear R6260
Netgear R6700V2
Netgear R6800
Netgear R6900V2
Netgear R7450