CVE-2017-6862
KEVmassBuffer Overflow in Multiple NETGEAR Devices Allows Auth Bypass and RCE
CISA: NETGEAR Multiple Devices Buffer Overflow Vulnerability
A buffer overflow (CWE-119) affects multiple NETGEAR networking devices and can be exploited remotely, allowing an attacker to bypass authentication on the device and potentially execute arbitrary code. The flaw is triggered when the affected device processes crafted network input, overflowing a memory buffer such that authentication checks can be bypassed or attacker-controlled code runs on the device. A successful attacker gains unauthorized access to the device's administrative functions or code execution on the device itself, providing a foothold for traffic interception, botnet enrollment, or pivoting into the network behind it. Any home or small-office operator running an affected NETGEAR model on unpatched firmware is affected; the specific model and firmware ranges are enumerated in NETGEAR's advisory rather than in this data. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS puts its 30-day exploitation probability at 42.7% (99th percentile), while no public PoC is cataloged and ransomware use is unknown.
What to do: Update affected NETGEAR devices to the fixed firmware listed in NETGEAR's security advisory for your exact model (check the model on the device label and the NETGEAR support page), since firmware is released per model. Until patched, disable or restrict remote/WAN administration so the web management interface is not exposed to the internet, and restrict admin access to trusted hosts. Because the flaw is on CISA's KEV catalog, federal agencies must patch by the required deadline, and defenders should prioritize any internet-exposed units.
| NETGEAR | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
- Affected
- NETGEAR Multiple Devices
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- netgear
- Products
- wnr2000 firmware
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H