Vulnerability Description
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, and R6100 before 1.0.1.20.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | R6100 Firmware | < 1.0.1.20 |
| Netgear | R6100 | - |
| Netgear | D6000 Firmware | < 1.0.0.67 |
| Netgear | D6000 | - |
| Netgear | D3600 Firmware | < 1.0.0.67 |
| Netgear | D3600 | - |
| Netgear | D6100 Firmware | < 1.0.0.56 |
| Netgear | D6100 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000055120/Security-Advisory-for-Pre-Authentication-BufferVendor Advisory
- https://kb.netgear.com/000055120/Security-Advisory-for-Pre-Authentication-BufferVendor Advisory
FAQ
What is CVE-2018-21217?
CVE-2018-21217 is a vulnerability with a CVSS score of 8.8 (HIGH). Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, and R6100 before 1.0.1.20.
How severe is CVE-2018-21217?
CVE-2018-21217 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-21217?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear R6100 Firmware, Netgear R6100, Netgear D6000 Firmware, Netgear D6000, Netgear D3600 Firmware.