ZeroHour

CVE-2017-6862

KEVmass

Buffer Overflow in Multiple NETGEAR Devices Allows Auth Bypass and RCE

CISA: NETGEAR Multiple Devices Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
43%p99
Published
()
KEV added
AI analysis

A buffer overflow (CWE-119) affects multiple NETGEAR networking devices and can be exploited remotely, allowing an attacker to bypass authentication on the device and potentially execute arbitrary code. The flaw is triggered when the affected device processes crafted network input, overflowing a memory buffer such that authentication checks can be bypassed or attacker-controlled code runs on the device. A successful attacker gains unauthorized access to the device's administrative functions or code execution on the device itself, providing a foothold for traffic interception, botnet enrollment, or pivoting into the network behind it. Any home or small-office operator running an affected NETGEAR model on unpatched firmware is affected; the specific model and firmware ranges are enumerated in NETGEAR's advisory rather than in this data. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS puts its 30-day exploitation probability at 42.7% (99th percentile), while no public PoC is cataloged and ransomware use is unknown.

What to do: Update affected NETGEAR devices to the fixed firmware listed in NETGEAR's security advisory for your exact model (check the model on the device label and the NETGEAR support page), since firmware is released per model. Until patched, disable or restrict remote/WAN administration so the web management interface is not exposed to the internet, and restrict admin access to trusted hosts. Because the flaw is on CISA's KEV catalog, federal agencies must patch by the required deadline, and defenders should prioritize any internet-exposed units.

Affected
NETGEAR
Estimated exposure
mass≈1M+ deployed NETGEAR devices, plausibly >100,000 internet-exposed (public-scan counts; exact unpatched count unknown) — NETGEAR is one of the largest consumer router vendors with a multi-million-unit installed base, and public internet scans routinely surface hundreds of thousands of exposed NETGEAR web management interfaces, although the number actually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

CISA Known Exploited Vulnerability
Affected
NETGEAR Multiple Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
netgear
Products
wnr2000 firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news