CVE-2018-21223: Buffer Overflow
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2018-21223?
D3600, D6000, D7800, R6100, R7500, R7500v2, R9000, WNDR3700v4.
What is the severity of CVE-2018-21223?
The vulnerability has a severity rating of 8.8 (high).
How does CVE-2018-21223 affect NETGEAR devices?
The vulnerability allows an unauthenticated attacker to perform a buffer overflow attack on the affected NETGEAR devices.
How can I fix the CVE-2018-21223 vulnerability?
Update the firmware of the affected NETGEAR devices to the latest version provided by NETGEAR.
Where can I find more information about CVE-2018-21223?
More information about the vulnerability can be found in the following Netgear knowledge base article: https://kb.netgear.com/000055114/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-and-Gateways-PSV-2017-2457