Buffer overflow in NETGEAR products - #VU70572

 

Buffer overflow in NETGEAR products - #VU70572

Published: January 2, 2023


Vulnerability identifier: #VU70572
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote administrator on the local network can trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

EAX80
RAX200
RAX75
RAX80
R7960P
R8000P
R7900
R8000
R6400v2
R7000
R7000P

Remediation

Install updates from vendor's website.

EAX80 - update to 1.0.1.64
R7900 - update to 1.0.4.38
R8000 - update to 1.0.4.68
R6400v2 - update to 1.0.4.122
RAX200 - update to 1.0.6.138
RAX75 - update to 1.0.6.138
RAX80 - update to 1.0.6.138
R7000 - update to 1.0.11.116
R7000P - update to 1.3.3.152
R7960P - update to 1.4.4.94
R8000P - update to 1.4.4.94

External References

Related Security Bulletins