NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
2017-05-26T20:29:00.177
2025-04-20T01:37:25.860
Deferred
a2826606-91e7-4eb6-899e-8484bd4575d5
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | wnr2000v5_firmware | < 1.0.0.42 | Yes |
Hardware | netgear | wnr2000v5 | - | No |
Operating System | netgear | wnr2000v4_firmware | < 1.0.0.66 | Yes |
Hardware | netgear | wnr2000v4 | - | No |
Operating System | netgear | wnr2000v3_firmware | < 1.1.2.14 | Yes |
Hardware | netgear | wnr2000v3 | - | No |