CVE-2021-34236: Buffer Overflow
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bdgeniecreateaccount.cgi' with a sufficiently long parameter 'registercountry'.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34236?
CVE-2021-34236 is a buffer overflow vulnerability in the Netgear R8000 Router with firmware v1.0.4.56.
How does CVE-2021-34236 affect Netgear R8000 Router?
CVE-2021-34236 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST request to '/bd_genie_create_account.cgi' with a long parameter 'register_country'.
What is the severity of CVE-2021-34236?
CVE-2021-34236 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-34236 on my Netgear R8000 Router?
To fix CVE-2021-34236, you should update your Netgear R8000 Router firmware to version 1.0.4.56 (or higher) provided by Netgear.
What is the Common Weakness Enumeration (CWE) associated with CVE-2021-34236?
The Common Weakness Enumeration (CWE) associated with CVE-2021-34236 are CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-120 (Buffer Copy without Checking Size of Input)