CVE-2022-24655

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
18/03/2022
Last modified:
25/03/2022

Description

A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:ex6100_firmware:201.0.2.28:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6100:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ex6200:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:cax80_firmware:2.1.2.6:*:*:*:*:*:*:*
cpe:2.3:h:netgear:cax80:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:dc112a_firmware:1.0.0.62:*:*:*:*:*:*:*
cpe:2.3:h:netgear:dc112a:-:*:*:*:*:*:*:*