← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-45638

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.68, D6400 before 1.0.0.102, D7000v2 before 1.0.0.74, D8500 before 1.0.3.60, DC112A before 1.0.0.56, R6300v2 before 1.0.4.50, R6400 before 1.0.1.68, R7000 before 1.0.11.116, R7100LG before 1.0.0.70, RBS40V before 2.6.2.8, RBW30 before 2.6.2.2, RS400 before 1.5.1.80, R7000P before 1.3.2.132, and R6900P before 1.3.2.132.

No Active Exploit Signals
CVSS Base Score
9.6
CRITICAL
Exploitability:2.9
Impact Score:6.1
EPSS Probability:1.47%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
netgear d6220_firmware all
netgear d6220 all
netgear d6400_firmware all
netgear d6400 all
netgear d7000v2_firmware all
netgear d7000v2 all
netgear d8500_firmware all
netgear d8500 all
netgear dc112a_firmware all
netgear dc112a all
netgear r6300v2_firmware all
netgear r6300v2 all
netgear r6400_firmware all
netgear r6400 all
netgear r7000_firmware all
netgear r7000 all
netgear r7100lg_firmware all
netgear r7100lg all
netgear r7000p_firmware all
netgear r7000p all
netgear rbs40v_firmware all
netgear rbs40v all
netgear rbw30_firmware all
netgear rbw30 all
netgear rs400_firmware all
netgear rs400 all
netgear r6900p_firmware all
netgear r6900p all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.474%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-12-25T00:00:00
Published2021-12-26T00:31:28
Last Updated2024-08-04T04:47:01

LINK COPIED TO CLIPBOARD