Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-36187


Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.


Published

2023-09-01T16:15:08.020

Last Modified

2024-11-21T08:09:23.400

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear cbr40_firmware < 2.5.0.24 Yes
Hardware netgear cbr40 - No
Operating System netgear lax20_firmware < 1.1.6.34 Yes
Hardware netgear lax20 - No
Operating System netgear mk62_firmware < 1.1.6.122 Yes
Hardware netgear mk62 - No
Operating System netgear mr60_firmware < 1.1.6.122 Yes
Hardware netgear mr60 - No
Operating System netgear ms60_firmware < 1.1.6.122 Yes
Hardware netgear ms60 - No
Operating System netgear rbw30_firmware < 2.6.2.6 Yes
Hardware netgear rbw30 - No
Operating System netgear r6400_firmware < 1.0.1.70 Yes
Hardware netgear r6400 - No
Operating System netgear r6400v2_firmware < 1.0.4.118 Yes
Hardware netgear r6400v2 - No
Operating System netgear r6700v3_firmware < 1.0.4.118 Yes
Hardware netgear r6700v3 - No
Operating System netgear r7000_firmware < 1.0.11.130 Yes
Hardware netgear r7000 - No
Operating System netgear r7000p_firmware < 1.3.3.148 Yes
Hardware netgear r7000p - No
Operating System netgear rax200_firmware < 1.0.4.120 Yes
Hardware netgear rax200 - No
Operating System netgear rax75_firmware < 1.0.4.120 Yes
Hardware netgear rax75 - No
Operating System netgear rax80_firmware < 1.0.4.120 Yes
Hardware netgear rax80 - No
Operating System netgear rs400_firmware < 1.5.1.86 Yes
Hardware netgear rs400 - No

References