CVE-2021-45611

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects DC112A before 1.0.0.52, R6400 before 1.0.1.68, RAX200 before 1.0.3.106, WNDR3400v3 before 1.0.1.38, XR300 before 1.0.3.68, R8500 before 1.0.2.144, RAX75 before 1.0.3.106, R8300 before 1.0.2.144, and RAX80 before 1.0.3.106.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
mitreCNA
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AC:L/AV:A/A:H/C:H/I:H/PR:N/S:C/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
netgeardc112a_firmware
𝑥
< 1.0.0.52
netgearr6400_firmware
𝑥
< 1.0.1.68
netgearr8300_firmware
𝑥
< 1.0.2.144
netgearr8500_firmware
𝑥
< 1.0.2.144
netgearwndr3400v3_firmware
𝑥
< 1.0.1.38
netgearxr300_firmware
𝑥
< 1.0.3.68
netgearrax200_firmware
𝑥
< 1.0.3.106
netgearrax75_firmware
𝑥
< 1.0.3.106
netgearrax80_firmware
𝑥
< 1.0.3.106
𝑥
= Vulnerable software versions