CVE-2018-21197: Buffer Overflow
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.34, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-21197?
CVE-2018-21197 is a vulnerability that affects certain NETGEAR devices, allowing an authenticated user to perform a stack-based buffer overflow.
Which devices are affected by CVE-2018-21197?
CVE-2018-21197 affects D7800 before 1.0.1.34, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, and WNDR4300 before 1.0.2.94.
What is the severity of CVE-2018-21197?
CVE-2018-21197 has a severity rating of 6.8 (medium).
How can an authenticated user exploit CVE-2018-21197?
An authenticated user can exploit CVE-2018-21197 by performing a stack-based buffer overflow attack.
Is there a fix available for CVE-2018-21197?
Yes, there are firmware updates available for the affected NETGEAR devices to fix CVE-2018-21197. Please refer to the NETGEAR advisory for more information.