Remote Code Execution Vulnerability in NETGEAR Router Products
CVE-2020-28373

8.8HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
9 November 2020

Summary

Certain NETGEAR devices exhibit a buffer overflow vulnerability in their upnpd service, allowing remote attackers on the local area network to execute arbitrary code. This security flaw impacts multiple router models and specific software versions, making them susceptible to malicious exploitation. Users are urged to review their device firmware and apply necessary updates to mitigate this risk.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.