Vulnerability Description
A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to remotely execute arbitrary code via a crafted UPnP SSDP packet.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Wndr3400V3 Firmware | >= 1.0.1.18, <= 1.0.1.24 |
| Netgear | Wndr3400V3 | - |
Related Weaknesses (CWE)
References
- https://github.com/reevesrs24/CVE/blob/master/Netgear_WNDR2400v3/upnp_stack_overExploitThird Party Advisory
- https://github.com/reevesrs24/CVE/blob/master/Netgear_WNDR2400v3/upnp_stack_overExploitThird Party Advisory
FAQ
What is CVE-2019-14363?
CVE-2019-14363 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to remotely execute arbitrary code via a crafted UPnP S...
How severe is CVE-2019-14363?
CVE-2019-14363 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-14363?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Wndr3400V3 Firmware, Netgear Wndr3400V3.