PT-2023-4729 · NetGear · Netgear R6400V2

·

CVE-2023-36187

·

Published

2023-03-15

·

Updated

2023-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR R6400v2 versions prior to 1.0.4.118
Description The issue is related to a Buffer Overflow in the httpd service of the NETGEAR R6400v2 Wi-Fi router's firmware, which can be exploited by remote unauthenticated attackers to execute arbitrary code. This can be achieved via a crafted URL to the httpd service. The exploitation may allow a remote attacker to execute arbitrary code using a specially crafted malicious web page.
Recommendations For versions prior to 1.0.4.118, update to version 1.0.4.118 or later to resolve the issue. As a temporary workaround, consider restricting access to the httpd service until a patch is applied. Avoid using crafted URLs that may trigger the Buffer Overflow vulnerability in the httpd service.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05160
CVE-2023-36187

Affected Products

Netgear R6400V2