CVE-2021-45573
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
26/12/2021
Last modified:
05/01/2022
Description
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6260 before 1.1.0.76, R6800 before 1.2.0.62, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, AC2100 before 1.2.0.62, AC2400 before 1.2.0.62, and AC2600 before 1.2.0.62.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netgear:r6260_firmware:*:*:*:*:*:*:*:* | 1.1.0.76 (excluding) | |
| cpe:2.3:h:netgear:r6260:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:r6800_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) | |
| cpe:2.3:h:netgear:r6800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) | |
| cpe:2.3:h:netgear:r6700:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) | |
| cpe:2.3:h:netgear:r6900:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:r7450_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) | |
| cpe:2.3:h:netgear:r7450:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ac2100_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) | |
| cpe:2.3:h:netgear:ac2100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ac2400_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) | |
| cpe:2.3:h:netgear:ac2400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:ac2600_firmware:*:*:*:*:*:*:*:* | 1.2.0.62 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



