← Back to CVE List
Vulnerability Intelligence Report

CVE-2018-21223

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
netgear d3600_firmware all
netgear d3600 all
netgear d6000_firmware all
netgear d6000 all
netgear d7800_firmware all
netgear d7800 all
netgear r6100_firmware all
netgear r6100 all
netgear r7500_firmware all
netgear r7500 v2
netgear r9000_firmware all
netgear r9000 all
netgear wndr3700_firmware all
netgear wndr3700 v4
netgear wndr4300_firmware all
netgear wndr4300 v2
netgear wndr4500_firmware all
netgear wndr4500 v3
netgear wnr2000_firmware all
netgear wnr2000 v5

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.629%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2020-04-20T00:00:00
Published2020-04-28T16:26:40
Patch Date2018-02-22
Last Updated2024-08-05T12:26:39

LINK COPIED TO CLIPBOARD