First published: Sun Dec 26 2021(Updated: )
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear D8500 Firmware | <1.0.3.58 | |
Netgear D8500 | ||
netgear R6250 Firmware | <1.0.4.48 | |
NETGEAR R6250 | ||
Netgear R7000 Firmware | <1.0.11.116 | |
NETGEAR R7000 | ||
Netgear R7000p Firmware | <1.3.2.132 | |
Netgear R7000P | ||
Netgear R6900p Firmware | <1.3.2.132 | |
Netgear R6900P | ||
Netgear R7900 Firmware | <1.0.4.38 | |
Netgear R7900 | ||
Netgear R8300 Firmware | <1.0.2.144 | |
NETGEAR R8300 | ||
Netgear R8500 Firmware | <1.0.2.144 | |
NETGEAR R8500 | ||
Netgear R7100lg Firmware | <1.0.0.64 | |
Netgear R7100LG | ||
Netgear Xr300 Firmware | <1.0.3.68 | |
Netgear XR300 | ||
All of | ||
Netgear D8500 Firmware | <1.0.3.58 | |
Netgear D8500 | ||
All of | ||
netgear R6250 Firmware | <1.0.4.48 | |
NETGEAR R6250 | ||
All of | ||
Netgear R7000 Firmware | <1.0.11.116 | |
NETGEAR R7000 | ||
All of | ||
Netgear R7000p Firmware | <1.3.2.132 | |
Netgear R7000P | ||
All of | ||
Netgear R6900p Firmware | <1.3.2.132 | |
Netgear R6900P | ||
All of | ||
Netgear R7900 Firmware | <1.0.4.38 | |
Netgear R7900 | ||
All of | ||
Netgear R8300 Firmware | <1.0.2.144 | |
NETGEAR R8300 | ||
All of | ||
Netgear R8500 Firmware | <1.0.2.144 | |
NETGEAR R8500 | ||
All of | ||
Netgear R7100lg Firmware | <1.0.0.64 | |
Netgear R7100LG | ||
All of | ||
Netgear Xr300 Firmware | <1.0.3.68 | |
Netgear XR300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45609 is a buffer overflow vulnerability in certain NETGEAR devices which allows an unauthenticated attacker to execute arbitrary code.
Devices affected by CVE-2021-45609 include D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.
CVE-2021-45609 has a severity score of 9.8, indicating a critical vulnerability.
An unauthenticated attacker can exploit CVE-2021-45609 by sending a specially crafted request, triggering a buffer overflow condition and potentially executing arbitrary code.
To mitigate CVE-2021-45609, it is recommended to update to the latest firmware version provided by NETGEAR, which addresses the buffer overflow vulnerability.