CVE-2021-45609

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6250 before 1.0.4.48, R7000 before 1.0.11.116, R7100LG before 1.0.0.64, R7900 before 1.0.4.38, R8300 before 1.0.2.144, R8500 before 1.0.2.144, XR300 before 1.0.3.68, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
mitreCNA
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
netgeard8500_firmware
𝑥
< 1.0.3.58
netgearr6250_firmware
𝑥
< 1.0.4.48
netgearr7000_firmware
𝑥
< 1.0.11.116
netgearr7000p_firmware
𝑥
< 1.3.2.132
netgearr6900p_firmware
𝑥
< 1.3.2.132
netgearr7900_firmware
𝑥
< 1.0.4.38
netgearr8300_firmware
𝑥
< 1.0.2.144
netgearr8500_firmware
𝑥
< 1.0.2.144
netgearr7100lg_firmware
𝑥
< 1.0.0.64
netgearxr300_firmware
𝑥
< 1.0.3.68
𝑥
= Vulnerable software versions