Input validation error in NETGEAR products - #VU61928

 

Input validation error in NETGEAR products - #VU61928

Published: April 6, 2022


Vulnerability identifier: #VU61928
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

R6120
D7000
R6260
R6330
R6350
R6850
R6220
R6230
AC2100
AC2400
R6700v2
R6900v2
R7200
R7350
R7400
R7450

Remediation

Install updates from vendor's website.

R6120 - update to 1.0.0.82
D7000 - update to 1.0.1.84
R6260 - update to 1.1.0.86
R6330 - update to 1.1.0.86
R6350 - update to 1.1.0.86
R6850 - update to 1.1.0.86
R6220 - update to 1.1.0.112
R6230 - update to 1.1.0.112
AC2100 - update to 1.2.0.90
AC2400 - update to 1.2.0.90
R6700v2 - update to 1.2.0.90
R6900v2 - update to 1.2.0.90
R7200 - update to 1.2.0.90
R7350 - update to 1.2.0.90
R7400 - update to 1.2.0.90
R7450 - update to 1.2.0.90

External References

Related Security Bulletins