Vulnerability Description
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, and R9000 before 1.0.2.52.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | R9000 Firmware | < 1.0.2.52 |
| Netgear | R9000 | - |
| Netgear | D6000 Firmware | < 1.0.0.67 |
| Netgear | D6000 | - |
| Netgear | D3600 Firmware | < 1.0.0.67 |
| Netgear | D3600 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000055116/Security-Advisory-for-Pre-Authentication-BufferVendor Advisory
- https://kb.netgear.com/000055116/Security-Advisory-for-Pre-Authentication-BufferVendor Advisory
FAQ
What is CVE-2018-21221?
CVE-2018-21221 is a vulnerability with a CVSS score of 8.8 (HIGH). Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, and R9000 before 1.0.2.52.
How severe is CVE-2018-21221?
CVE-2018-21221 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-21221?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear R9000 Firmware, Netgear R9000, Netgear D6000 Firmware, Netgear D6000, Netgear D3600 Firmware.