CVE-2019-14363: Buffer Overflow
Published Jul 28, 2019
·Updated
A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.181.0.63 allows an attacker to remotely execute arbitrary code via a crafted UPnP SSDP packet.
Affected Software
2 affected components
Netgear Wndr3400v3 Firmware>=1.0.1.18<=1.0.1.24
Netgear WNDR3400v3
Event History
Jul 28, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
Description
Frequently Asked Questions
1
What is CVE-2019-14363?
CVE-2019-14363 is a vulnerability in the upnpd binary running on NETGEAR WNDR3400v3 routers.
2
How severe is CVE-2019-14363?
CVE-2019-14363 has a severity rating of 9.8 (critical).
3
How does CVE-2019-14363 allow remote code execution?
CVE-2019-14363 allows remote code execution by exploiting a stack-based buffer overflow in the upnpd binary via a crafted UPnP SSDP packet.
4
Which routers are affected by CVE-2019-14363?
NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 are affected by CVE-2019-14363.
5
How can CVE-2019-14363 be fixed?
To fix CVE-2019-14363, update the firmware of the affected NETGEAR WNDR3400v3 router to version 1.0.1.24 or above.