Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.
References
Link | Resource |
---|---|
https://hdwsec.fr/blog/20221109-netgear/ | Broken Link |
https://www.netgear.com/about/security/ | Vendor Advisory |
https://kb.netgear.com/000065242/Security-Advisory-for-Pre-authentication-Stack-Overflow-on-some-Routers-and-Nighthawk-WiFi-Mesh-Systems-PSV-2022-0146 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
08 Feb 2023, 02:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:netgear:r6900p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:mr60:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r8000p:-:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7960p:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:ms60:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-787 | |
References | (MISC) https://kb.netgear.com/000065242/Security-Advisory-for-Pre-authentication-Stack-Overflow-on-some-Routers-and-Nighthawk-WiFi-Mesh-Systems-PSV-2022-0146 - Patch, Vendor Advisory | |
References | (MISC) https://hdwsec.fr/blog/20221109-netgear/ - Broken Link | |
References | (MISC) https://www.netgear.com/about/security/ - Vendor Advisory | |
First Time |
Netgear r7960p Firmware
Netgear ms60 Netgear mr60 Netgear r6900p Netgear Netgear r7000p Firmware Netgear r8000p Firmware Netgear r7960p Netgear r8000p Netgear r7000p Netgear ms60 Firmware Netgear mr60 Firmware Netgear r6900p Firmware |
31 Jan 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-01-31 00:15
Updated : 2023-02-08 02:02
NVD link : CVE-2022-48176
Mitre link : CVE-2022-48176
CVE.ORG link : CVE-2022-48176
JSON object : View
Products Affected
netgear
- r6900p_firmware
- r7000p_firmware
- r7960p_firmware
- r8000p
- mr60
- ms60_firmware
- ms60
- r6900p
- r8000p_firmware
- r7960p
- mr60_firmware
- r7000p
CWE
CWE-787
Out-of-bounds Write