First published: Fri Sep 01 2023(Updated: )
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Cbr40 Firmware | <2.5.0.24 | |
Netgear Cbr40 | ||
Netgear Lax20 Firmware | <1.1.6.34 | |
Netgear Lax20 | ||
Netgear Mk62 Firmware | <1.1.6.122 | |
Netgear Mk62 | ||
Netgear Mr60 Firmware | <1.1.6.122 | |
Netgear Mr60 | ||
Netgear Ms60 Firmware | <1.1.6.122 | |
Netgear Ms60 | ||
Netgear Rbw30 Firmware | <2.6.2.6 | |
Netgear Rbw30 | ||
Netgear R6400 Firmware | <1.0.1.70 | |
NETGEAR R6400 | ||
Netgear R6400v2 Firmware | <1.0.4.118 | |
NETGEAR R6400v2 | ||
Netgear R6700v3 Firmware | <1.0.4.118 | |
NETGEAR R6700v3 | ||
Netgear R7000 Firmware | <1.0.11.130 | |
NETGEAR R7000 | ||
Netgear R7000p Firmware | <1.3.3.148 | |
Netgear R7000P | ||
Netgear Rax200 Firmware | <1.0.4.120 | |
NETGEAR RAX200 | ||
Netgear Rax75 Firmware | <1.0.4.120 | |
Netgear Rax75 | ||
Netgear Rax80 Firmware | <1.0.4.120 | |
Netgear Rax80 | ||
Netgear Rs400 Firmware | <1.5.1.86 | |
Netgear Rs400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36187 is a buffer overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118.
CVE-2023-36187 has a severity rating of 9.8 (Critical).
CVE-2023-36187 allows remote unauthenticated attackers to execute arbitrary code via a crafted URL to httpd on NETGEAR R6400v2 before version 1.0.4.118.
No, there may be other affected devices. Please refer to the NETGEAR security advisory for more information.
To fix CVE-2023-36187, you should update NETGEAR R6400v2 to version 1.0.4.118 or later as recommended in the NETGEAR security advisory.