← Back

CVE-2020-28373

nvd nist
Published: Nov 9, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overflow. This affects R6400v2 V1.0.4.102_10.0.75, R6400 V1.0.1.62_1.0.41, R7000P V1.3.2.126_10.1.66, XR300 V1.0.3.50_10.3.36, R8000 V1.0.4.62, R8300 V1.0.2.136, R8500 V1.0.2.136, R7300DST V1.0.0.74, R7850 V1.0.5.64, R7900 V1.0.4.30, RAX20 V1.0.2.64, RAX80 V1.0.3.102, and R6250 V1.0.4.44.

Affected (13)

13 products
R6400v2 Firmware
R6400 Firmware
R7000p Firmware
Xr300 Firmware
R8000 Firmware
R8300 Firmware
R8500 Firmware
R7300dst Firmware
R7850 Firmware
R7900 Firmware
Rax20 Firmware
Rax80 Firmware
R6250 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.102_10.0.75
Running on/withPlatform Versions
Netgear
R6400v2
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.1.62_1.0.41
Running on/withPlatform Versions
Netgear
R6400
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.2.126_10.1.66
Running on/withPlatform Versions
Netgear
R7000p
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.3.50_10.3.36
Running on/withPlatform Versions
Netgear
Xr300
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.62
Running on/withPlatform Versions
Netgear
R8000
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2.136
Running on/withPlatform Versions
Netgear
R8300
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2.136
Running on/withPlatform Versions
Netgear
R8500
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.0.74
Running on/withPlatform Versions
Netgear
R7300dst
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.5.64
Running on/withPlatform Versions
Netgear
R7850
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.30
Running on/withPlatform Versions
Netgear
R7900
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.2.64
Running on/withPlatform Versions
Netgear
Rax20
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.3.102
Running on/withPlatform Versions
Netgear
Rax80
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.4.44
Running on/withPlatform Versions
Netgear
R6250
All versions

References (2)

Source: cve@mitre.org
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory

Timeline

No history available yet.