CVE-2021-38524

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX45 before 1.0.2.32, RAX50 before 1.0.2.32, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, and RBS750 before 3.2.16.6.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:mk62_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mk62:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:rax15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax15:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax20:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:rax200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax200:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:rax75_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax75:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax80:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netgear:rbk752_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk752:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*

History

19 Aug 2021, 11:57

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:h:netgear:rax20:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax75_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax80:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbk752:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mk62:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax200:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax45:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbr750:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax75:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbk752_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax50:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rax15:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rax15_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:rbs750:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:mk62_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.9
References (MISC) https://kb.netgear.com/000063779/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-Some-Routers-and-WiFi-Systems-PSV-2020-0225 - (MISC) https://kb.netgear.com/000063779/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-Some-Routers-and-WiFi-Systems-PSV-2020-0225 - Vendor Advisory

11 Aug 2021, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-11 00:16

Updated : 2023-12-10 13:55


NVD link : CVE-2021-38524

Mitre link : CVE-2021-38524

CVE.ORG link : CVE-2021-38524


JSON object : View

Products Affected

netgear

  • mr60_firmware
  • rbr750
  • rax75_firmware
  • rax80_firmware
  • ms60_firmware
  • rax200
  • rbs750_firmware
  • rbs750
  • rax200_firmware
  • rax20
  • mk62_firmware
  • rax15
  • rax45
  • rax50
  • mr60
  • rbk752_firmware
  • mk62
  • rax45_firmware
  • rax50_firmware
  • rbk752
  • rbr750_firmware
  • rax80
  • rax20_firmware
  • rax15_firmware
  • ms60
  • rax75
CWE
CWE-787

Out-of-bounds Write