First published: Fri Sep 01 2023(Updated: )
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR CBR40 firmware | <2.5.0.24 | |
Netgear CBR40 | ||
NETGEAR LAX20 firmware | <1.1.6.34 | |
NETGEAR LAX20 | ||
NETGEAR MK62 | <1.1.6.122 | |
NETGEAR MK62 firmware | ||
NETGEAR MR60 firmware | <1.1.6.122 | |
NETGEAR MR60 firmware | ||
NETGEAR MS60 | <1.1.6.122 | |
NETGEAR MS60 firmware | ||
NETGEAR RBW30 firmware | <2.6.2.6 | |
NETGEAR RBW30 firmware | ||
NETGEAR R6400 firmware | <1.0.1.70 | |
NETGEAR R6400 firmware | ||
NETGEAR R6400v2 firmware | <1.0.4.118 | |
NETGEAR R6400v2 firmware | ||
Netgear R6700 Firmware | <1.0.4.118 | |
NETGEAR R6700v3 firmware | ||
NETGEAR R7000 firmware | <1.0.11.130 | |
NETGEAR R7000 firmware | ||
NETGEAR R7000P firmware | <1.3.3.148 | |
Netgear R7000P | ||
NETGEAR RAX200 firmware | <1.0.4.120 | |
NETGEAR RAX200 firmware | ||
NETGEAR RAX75 firmware | <1.0.4.120 | |
NETGEAR RAX75 firmware | ||
NETGEAR RAX80 firmware | <1.0.4.120 | |
NETGEAR RAX80 firmware | ||
NETGEAR RS400 firmware | <1.5.1.86 | |
NETGEAR RS400 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36187 is a buffer overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118.
CVE-2023-36187 has a severity rating of 9.8 (Critical).
CVE-2023-36187 allows remote unauthenticated attackers to execute arbitrary code via a crafted URL to httpd on NETGEAR R6400v2 before version 1.0.4.118.
No, there may be other affected devices. Please refer to the NETGEAR security advisory for more information.
To fix CVE-2023-36187, you should update NETGEAR R6400v2 to version 1.0.4.118 or later as recommended in the NETGEAR security advisory.