CVE-2020-28373: Buffer Overflow
upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overflow. This affects R6400v2 V1.0.4.10210.0.75, R6400 V1.0.1.621.0.41, R7000P V1.3.2.12610.1.66, XR300 V1.0.3.5010.3.36, R8000 V1.0.4.62, R8300 V1.0.2.136, R8500 V1.0.2.136, R7300DST V1.0.0.74, R7850 V1.0.5.64, R7900 V1.0.4.30, RAX20 V1.0.2.64, RAX80 V1.0.3.102, and R6250 V1.0.4.44.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28373?
CVE-2020-28373 is a vulnerability that allows remote attackers to execute arbitrary code on certain NETGEAR devices via a stack-based buffer overflow.
Which NETGEAR devices are affected by CVE-2020-28373?
CVE-2020-28373 affects the following NETGEAR devices: R6400v2, R6400, R7000P, XR300, R8000, R8300, R8500, and R7300D.
What is the severity of CVE-2020-28373?
CVE-2020-28373 has a severity rating of 8.8 (High).
How can remote (LAN) attackers exploit CVE-2020-28373?
Remote (LAN) attackers can exploit CVE-2020-28373 by leveraging a stack-based buffer overflow vulnerability in the upnpd service on vulnerable NETGEAR devices.
Is there a fix available for CVE-2020-28373?
At present, there is no official fix available for CVE-2020-28373. It is recommended to disable the upnpd service on affected NETGEAR devices or implement network-level mitigations.