CVE-2019-20735

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before V1.0.0.75, D6100 before V1.0.0.63, R7800 before v1.0.2.52, R8900 before v1.0.4.2, R9000 before v1.0.4.2, RBK50 before v2.3.0.32, RBR50 before v2.3.0.32, RBS50 before v2.3.0.32, WNDR3700v4 before V1.0.2.102, WNDR4300v1 before V1.0.2.104, WNDR4300v2 before v1.0.0.58, WNDR4500v3 before v1.0.0.58, WNR2000v5 before v1.0.0.68, and XR500 before V2.3.2.32.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
6.8 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.0/AC:L/AV:A/A:H/C:H/I:H/PR:H/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
netgeard3600_firmware
𝑥
< 1.0.0.75
netgeard6000_firmware
𝑥
< 1.0.0.75
netgeard6100_firmware
𝑥
< 1.0.0.63
netgearr7800_firmware
𝑥
< 1.0.2.52
netgearr8900_firmware
𝑥
< 1.0.4.2
netgearr9000_firmware
𝑥
< 1.0.4.2
netgearrbk50_firmware
𝑥
< 2.3.0.32
netgearrbr50_firmware
𝑥
< 2.3.0.32
netgearrbs50_firmware
𝑥
< 2.3.0.32
netgearwndr3700_firmware
𝑥
< 1.0.2.102
netgearwndr4300_firmware
𝑥
< 1.0.2.104
netgearwndr4300_firmware
𝑥
< 1.0.0.58
netgearwndr4500_firmware
𝑥
< 1.0.0.58
netgearwnr2000_firmware
𝑥
< 1.0.0.68
netgearxr500_firmware
𝑥
< 2.3.2.32
𝑥
= Vulnerable software versions