Buffer Overflow Vulnerability in Netgear Routers
CVE-2024-12988

7.5HIGH

Key Information:

Vendor

Netgear

Vendor
CVE Published:
27 December 2024

What is CVE-2024-12988?

A vulnerability identified in Netgear R6900P and R7000P affects the HTTP Header Handler component, specifically within the function responsible for processing the Host argument. Malicious exploitation of this vulnerability can lead to a buffer overflow, potentially enabling attackers to execute arbitrary code remotely. The vulnerability has been publicly disclosed, creating a heightened risk for users and necessitating prompt remedial action. Despite prior notifications, Netgear has not addressed the concerns raised regarding this critical issue.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.