9.8

CVE-2023-36187

Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.

Data is provided by the National Vulnerability Database (NVD)
NetgearCbr40 Firmware Version < 2.5.0.24
   NetgearCbr40 Version-
NetgearLax20 Firmware Version < 1.1.6.34
   NetgearLax20 Version-
NetgearMk62 Firmware Version < 1.1.6.122
   NetgearMk62 Version-
NetgearMr60 Firmware Version < 1.1.6.122
   NetgearMr60 Version-
NetgearMs60 Firmware Version < 1.1.6.122
   NetgearMs60 Version-
NetgearRbw30 Firmware Version < 2.6.2.6
   NetgearRbw30 Version-
NetgearR6400 Firmware Version < 1.0.1.70
   NetgearR6400 Version-
NetgearR6400v2 Firmware Version < 1.0.4.118
   NetgearR6400v2 Version-
NetgearR6700v3 Firmware Version < 1.0.4.118
   NetgearR6700v3 Version-
NetgearR7000 Firmware Version < 1.0.11.130
   NetgearR7000 Version-
NetgearR7000p Firmware Version < 1.3.3.148
   NetgearR7000p Version-
NetgearRax200 Firmware Version < 1.0.4.120
   NetgearRax200 Version-
NetgearRax75 Firmware Version < 1.0.4.120
   NetgearRax75 Version-
NetgearRax80 Firmware Version < 1.0.4.120
   NetgearRax80 Version-
NetgearRs400 Firmware Version < 1.5.1.86
   NetgearRs400 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.54% 0.885
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.