CVE-2022-24655
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.
Affected (4)
Products: Netgear: Ex6100 Firmware, Ex6200 Firmware, Cax80 Firmware, Dc112a Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 201.0.2.28 |
| Running on/with | Platform Versions |
|---|---|
Netgear Ex6100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netgear Ex6200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.1.2.6 |
| Running on/with | Platform Versions |
|---|---|
Netgear Cax80 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.62 |
| Running on/with | Platform Versions |
|---|---|
Netgear Dc112a | All versions |
References (6)
Source: cve@mitre.org
ExploitPatchThird Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.