CVE-2018-21194: Buffer Overflow
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, D7800 before 1.0.1.34, R6100 before 1.0.1.20, R7500 before 1.0.0.122, R7500v2 before 1.0.3.24, R7800 before 1.0.2.40, R9000 before 1.0.3.6, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2018-21194?
D6100, D7800, R6100, R7500, R7500v2, R7800, R9000, WNDR3700v4, WNDR4300, WNDR4500, and WNR2000.
What is the severity of CVE-2018-21194?
The severity of CVE-2018-21194 is medium.
How does the authenticated user trigger the stack-based buffer overflow in CVE-2018-21194?
The authenticated user triggers the stack-based buffer overflow through a specific request to the affected NETGEAR device.
How can I fix CVE-2018-21194?
Apply the latest firmware update provided by NETGEAR to the affected device.
Where can I find more information about CVE-2018-21194?
You can find more information about CVE-2018-21194 in the NETGEAR security advisory linked in the references.