CVE-2021-45525: Buffer Overflow
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects EX7000 before 1.0.1.80, R6400 before 1.0.1.50, R6400v2 before 1.0.4.118, R6700 before 1.0.2.8, R6700v3 before 1.0.4.118, R6900 before 1.0.2.8, R6900P before 1.3.2.124, R7000 before 1.0.9.88, R7000P before 1.3.2.124, R7900 before 1.0.3.18, R7900P before 1.4.1.50, R8000 before 1.0.4.46, R8000P before 1.4.1.50, RAX80 before 1.0.1.56, and WNR3500Lv2 before 1.2.0.62.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2021-45525?
The NETGEAR devices affected by CVE-2021-45525 include EX7000, R6400, R6400v2, R6700, R6700v3, R6900, R6900P, R7000, R7000P, R7900, R8000, R8000P, and Rax80.
What is the severity rating for CVE-2021-45525?
The severity rating for CVE-2021-45525 is 8.8 (High).
How can an authenticated user exploit the buffer overflow vulnerability in CVE-2021-45525?
An authenticated user can exploit the buffer overflow vulnerability in CVE-2021-45525 by sending a specially crafted request, leading to remote code execution.
Is there a fix available for CVE-2021-45525?
Yes, NETGEAR has released firmware updates to address the buffer overflow vulnerability in CVE-2021-45525. Users should update their devices to the latest firmware version provided by NETGEAR.
Where can I find more information about CVE-2021-45525?
More information about CVE-2021-45525 can be found on the NETGEAR Security Advisory page: https://kb.netgear.com/000064052/Security-Advisory-for-Post-Authentication-Buffer-Overflow-on-Some-Routers-and-Extenders-PSV-2018-0618