Integer Overflow Vulnerability in D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital Products
CVE-2021-45608
6.5MEDIUM
Summary
Several consumer routers from vendors like D-Link, NETGEAR, and TP-Link are susceptible to an integer overflow issue, potentially allowing unauthenticated remote attackers to exploit this vulnerability. While the vulnerability resides within the KCodes NetUSB kernel module's SoftwareBus_dispatchNormalEPMsgOut function, its exploitation complexity is notably high. This flaw could lead to remote code execution through the WAN interface, specifically via TCP port 20005. Security measures and software updates are crucial to protecting against this type of attack, given the potential risk associated with the overflow issue.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved