PT-2023-4729 · NetGear · Netgear R6400V2
Swings
·
Published
2023-03-15
·
Updated
2023-09-07
·
CVE-2023-36187
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NETGEAR R6400v2 versions prior to 1.0.4.118
Description
The issue is related to a Buffer Overflow in the httpd service of the NETGEAR R6400v2 Wi-Fi router's firmware, which can be exploited by remote unauthenticated attackers to execute arbitrary code. This can be achieved via a crafted URL to the
httpd service. The exploitation may allow a remote attacker to execute arbitrary code using a specially crafted malicious web page.Recommendations
For versions prior to 1.0.4.118, update to version 1.0.4.118 or later to resolve the issue. As a temporary workaround, consider restricting access to the
httpd service until a patch is applied. Avoid using crafted URLs that may trigger the Buffer Overflow vulnerability in the httpd service.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear R6400V2