Vulnerability Description
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | R7800 Firmware | < 1.0.2.40 |
| Netgear | R7800 | - |
| Netgear | Ex2700 Firmware | < 1.0.1.28 |
| Netgear | Ex2700 | - |
| Netgear | Wn2000Rpt Firmware | < 1.0.1.20 |
| Netgear | Wn2000Rpt | v3 |
| Netgear | Wn3000Rp Firmware | < 1.0.2.50 |
| Netgear | Wn3000Rp | v3 |
| Netgear | Wn3100Rp Firmware | < 1.0.0.56 |
| Netgear | Wn3100Rp | v2 |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000055188/Security-Advisory-for-Pre-Authentication-Stack-Vendor Advisory
- https://kb.netgear.com/000055188/Security-Advisory-for-Pre-Authentication-Stack-Vendor Advisory
FAQ
What is CVE-2018-21170?
CVE-2018-21170 is a vulnerability with a CVSS score of 8.8 (HIGH). Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv...
How severe is CVE-2018-21170?
CVE-2018-21170 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-21170?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear R7800 Firmware, Netgear R7800, Netgear Ex2700 Firmware, Netgear Ex2700, Netgear Wn2000Rpt Firmware.