CVE-2021-38524
Summary
| CVE | CVE-2021-38524 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-11 00:16:00 UTC |
| Updated | 2021-08-19 11:57:00 UTC |
| Description | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX45 before 1.0.2.32, RAX50 before 1.0.2.32, RAX75 before 1.0.3.106, RAX80 before 1.0.3.106, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, and RBS750 before 3.2.16.6. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | Mk62 | - | All | All | All |
| Operating System | Netgear | Mk62 Firmware | All | All | All | All |
| Hardware | Netgear | Mr60 | - | All | All | All |
| Operating System | Netgear | Mr60 Firmware | All | All | All | All |
| Hardware | Netgear | Ms60 | - | All | All | All |
| Operating System | Netgear | Ms60 Firmware | All | All | All | All |
| Hardware | Netgear | Rax15 | - | All | All | All |
| Operating System | Netgear | Rax15 Firmware | All | All | All | All |
| Hardware | Netgear | Rax20 | - | All | All | All |
| Hardware | Netgear | Rax200 | - | All | All | All |
| Operating System | Netgear | Rax200 Firmware | All | All | All | All |
| Operating System | Netgear | Rax20 Firmware | All | All | All | All |
| Hardware | Netgear | Rax45 | - | All | All | All |
| Operating System | Netgear | Rax45 Firmware | All | All | All | All |
| Hardware | Netgear | Rax50 | - | All | All | All |
| Operating System | Netgear | Rax50 Firmware | All | All | All | All |
| Hardware | Netgear | Rax75 | - | All | All | All |
| Operating System | Netgear | Rax75 Firmware | All | All | All | All |
| Hardware | Netgear | Rax80 | - | All | All | All |
| Operating System | Netgear | Rax80 Firmware | All | All | All | All |
| Hardware | Netgear | Rbk752 | - | All | All | All |
| Operating System | Netgear | Rbk752 Firmware | All | All | All | All |
| Hardware | Netgear | Rbr750 | - | All | All | All |
| Operating System | Netgear | Rbr750 Firmware | All | All | All | All |
| Hardware | Netgear | Rbs750 | - | All | All | All |
| Operating System | Netgear | Rbs750 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory for Post-Authentication Stack Overflow on Some Routers and WiFi Systems, PSV-2020-0225 | Answer | NETGEAR Support | MISC | kb.netgear.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.