CVE-2023-36187

Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
netgearcbr40_firmware
𝑥
< 2.5.0.24
netgearlax20_firmware
𝑥
< 1.1.6.34
netgearmk62_firmware
𝑥
< 1.1.6.122
netgearmr60_firmware
𝑥
< 1.1.6.122
netgearms60_firmware
𝑥
< 1.1.6.122
netgearrbw30_firmware
𝑥
< 2.6.2.6
netgearr6400_firmware
𝑥
< 1.0.1.70
netgearr6400v2_firmware
𝑥
< 1.0.4.118
netgearr6700v3_firmware
𝑥
< 1.0.4.118
netgearr7000_firmware
𝑥
< 1.0.11.130
netgearr7000p_firmware
𝑥
< 1.3.3.148
netgearrax200_firmware
𝑥
< 1.0.4.120
netgearrax75_firmware
𝑥
< 1.0.4.120
netgearrax80_firmware
𝑥
< 1.0.4.120
netgearrs400_firmware
𝑥
< 1.5.1.86
𝑥
= Vulnerable software versions