First published: Tue Mar 23 2021(Updated: )
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R8000P before 1.4.1.66, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, R7960P before 1.4.1.66, R7900P before 1.4.1.66, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, and RAX200 before 1.0.3.106.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R8000p Firmware | <1.4.1.66 | |
Netgear R8000p | ||
Netgear Mk62 Firmware | <1.0.6.110 | |
Netgear Mk62 | ||
Netgear Mr60 Firmware | <1.0.6.110 | |
Netgear Mr60 | ||
Netgear Ms60 Firmware | <1.0.6.110 | |
Netgear Ms60 | ||
Netgear R7960p Firmware | <1.4.1.66 | |
Netgear R7960p | ||
Netgear R7900p Firmware | <1.4.1.66 | |
Netgear R7900p | ||
Netgear Rax15 Firmware | <1.0.2.82 | |
Netgear Rax15 | ||
Netgear Rax20 Firmware | <1.0.2.82 | |
Netgear Rax20 | ||
Netgear Rax45 Firmware | <1.0.2.72 | |
Netgear Rax45 | ||
Netgear Rax50 Firmware | <1.0.2.72 | |
Netgear Rax50 | ||
Netgear Rax75 Firmware | <1.0.3.106 | |
Netgear Rax75 | ||
Netgear Rax80 Firmware | <1.0.3.106 | |
Netgear Rax80 | ||
Netgear Rax200 Firmware | <1.0.3.106 | |
NETGEAR RAX200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for this issue is CVE-2021-29073.
This vulnerability affects certain NETGEAR devices including R8000P, MK62, MR60, MS60, R7960P, R7900P, RAX15, RAX20, RAX45, RAX50, RAX75, RAX80, and RAX200.
The severity rating of CVE-2021-29073 is high, with a score of 8.4.
The vulnerability manifests as a stack-based buffer overflow that can be exploited by an authenticated user.
To fix the vulnerability, update the firmware of the affected NETGEAR devices to versions 1.4.1.66, 1.0.6.110, 1.0.2.82, 1.0.2.72, 1.0.3.106, or later.