Integer Overflow Vulnerability in D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital Products
CVE-2021-45608

6.5MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
26 December 2021

Summary

Several consumer routers from vendors like D-Link, NETGEAR, and TP-Link are susceptible to an integer overflow issue, potentially allowing unauthenticated remote attackers to exploit this vulnerability. While the vulnerability resides within the KCodes NetUSB kernel module's SoftwareBus_dispatchNormalEPMsgOut function, its exploitation complexity is notably high. This flaw could lead to remote code execution through the WAN interface, specifically via TCP port 20005. Security measures and software updates are crucial to protecting against this type of attack, given the potential risk associated with the overflow issue.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.