CVE-2020-35795

Published: Dic 30, 2020 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2020-23450 Aliases: GSD-2020-35795
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH 7,5
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D7800 before 1.0.1.58, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX7500 before 1.0.0.68, MK62 before 1.0.5.102, MR60 before 1.0.5.102, MS60 before 1.0.5.102, R6120 before 1.0.0.70, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.76, R6330 before 1.1.0.76, R6350 before 1.1.0.76, R6400 before 1.0.1.62, R6400v2 before 1.0.4.98, R6700 before 1.0.2.16, R6700v2 before 1.2.0.72, R6700v3 before 1.0.4.98, R6800 before 1.2.0.72, R6850 before 1.1.0.76, R6900P before 1.3.2.124, R6900 before 1.0.2.16, R6900v2 before 1.2.0.72, R7000 before 1.0.11.106, R7000P before 1.3.2.124, R7200 before 1.2.0.72, R7350 before 1.2.0.72, R7400 before 1.2.0.72, R7450 before 1.2.0.72, R7800 before 1.0.2.74, R7850 before 1.0.5.60, R7900 before 1.0.4.26, R7900P before 1.4.1.62, R7960P before 1.4.1.62, R8000 before 1.0.4.58, R8000P before 1.4.1.62, R8900 before 1.0.5.24, R9000 before 1.0.5.24, RAX120 before 1.0.1.136, RAX15 before 1.0.1.64, RAX20 before 1.0.1.64, RAX200 before 1.0.2.102, RAX45 before 1.0.2.64, RAX50 before 1.0.2.64, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK12 before 2.6.1.44, RBR10 before 2.6.1.44, RBS10 before 2.6.1.44, RBK20 before 2.6.1.38, RBR20 before 2.6.1.36, RBS20 before 2.6.1.38, RBK40 before 2.6.1.38, RBR40 before 2.6.1.36, RBS40 before 2.6.1.38, RBK50 before 2.6.1.40, RBR50 before 2.6.1.40, RBS50 before 2.6.1.40, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK842 before 3.2.16.6, RBR840 before 3.2.16.6, RBS840 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, RBS850 before 3.2.16.6, RS400 before 1.5.0.48, XR300 before 1.0.3.50, XR450 before 2.3.2.66, XR500 before 2.3.2.66, and XR700 before 1.0.1.34.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0056
Percentile
0,7th
Updated

EPSS Score Trend (Last 90 Days)

120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Modify Memory Execute Unauthorized Code Or Commands Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu)
Applicable Platforms
Languages: Assembly, C, C++, Memory-Unsafe
View CWE Details
Operating System

R7200 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r7200_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6900V2 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r6900v2_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs850 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbs850_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs20 Firmware by Netgear

Version Range Affected
To 2.6.1.38 (exclusive)
cpe:2.3:o:netgear:rbs20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Xr450 Firmware by Netgear

Version Range Affected
To 2.3.2.66 (exclusive)
cpe:2.3:o:netgear:xr450_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr750 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbr750_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ms60 Firmware by Netgear

Version Range Affected
To 1.0.5.102 (exclusive)
cpe:2.3:o:netgear:ms60_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk40 Firmware by Netgear

Version Range Affected
To 2.6.1.38 (exclusive)
cpe:2.3:o:netgear:rbk40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Xr500 Firmware by Netgear

Version Range Affected
To 2.3.2.66 (exclusive)
cpe:2.3:o:netgear:xr500_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R9000 Firmware by Netgear

Version Range Affected
To 1.0.5.24 (exclusive)
cpe:2.3:o:netgear:r9000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6700 Firmware by Netgear

Version Range Affected
To 1.0.2.16 (exclusive)
cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr40 Firmware by Netgear

Version Range Affected
To 2.6.1.36 (exclusive)
cpe:2.3:o:netgear:rbr40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs50 Firmware by Netgear

Version Range Affected
To 2.6.1.40 (exclusive)
cpe:2.3:o:netgear:rbs50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7400 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r7400_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6260 Firmware by Netgear

Version Range Affected
To 1.1.0.76 (exclusive)
cpe:2.3:o:netgear:r6260_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs10 Firmware by Netgear

Version Range Affected
To 2.6.1.44 (exclusive)
cpe:2.3:o:netgear:rbs10_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Cbr40 Firmware by Netgear

Version Range Affected
To 2.5.0.10 (exclusive)
cpe:2.3:o:netgear:cbr40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6230 Firmware by Netgear

Version Range Affected
To 1.1.0.100 (exclusive)
cpe:2.3:o:netgear:r6230_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs750 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbs750_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax20 Firmware by Netgear

Version Range Affected
To 1.0.1.64 (exclusive)
cpe:2.3:o:netgear:rax20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6850 Firmware by Netgear

Version Range Affected
To 1.1.0.76 (exclusive)
cpe:2.3:o:netgear:r6850_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr50 Firmware by Netgear

Version Range Affected
To 2.6.1.40 (exclusive)
cpe:2.3:o:netgear:rbr50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R8000P Firmware by Netgear

Version Range Affected
To 1.4.1.62 (exclusive)
cpe:2.3:o:netgear:r8000p_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Mr60 Firmware by Netgear

Version Range Affected
To 1.0.5.102 (exclusive)
cpe:2.3:o:netgear:mr60_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7850 Firmware by Netgear

Version Range Affected
To 1.0.5.60 (exclusive)
cpe:2.3:o:netgear:r7850_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7900P Firmware by Netgear

Version Range Affected
To 1.4.1.62 (exclusive)
cpe:2.3:o:netgear:r7900p_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr840 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbr840_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6400 Firmware by Netgear

Version Range Affected
To 1.0.1.62 (exclusive)
cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax200 Firmware by Netgear

Version Range Affected
To 1.0.2.102 (exclusive)
cpe:2.3:o:netgear:rax200_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ac2600 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:ac2600_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs840 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbs840_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ac2100 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:ac2100_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R8900 Firmware by Netgear

Version Range Affected
To 1.0.5.24 (exclusive)
cpe:2.3:o:netgear:r8900_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax45 Firmware by Netgear

Version Range Affected
To 1.0.2.64 (exclusive)
cpe:2.3:o:netgear:rax45_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7000P Firmware by Netgear

Version Range Affected
To 1.3.2.124 (exclusive)
cpe:2.3:o:netgear:r7000p_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6900P Firmware by Netgear

Version Range Affected
To 1.3.2.124 (exclusive)
cpe:2.3:o:netgear:r6900p_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Eax20 Firmware by Netgear

Version Range Affected
To 1.0.0.36 (exclusive)
cpe:2.3:o:netgear:eax20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7450 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r7450_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6330 Firmware by Netgear

Version Range Affected
To 1.1.0.76 (exclusive)
cpe:2.3:o:netgear:r6330_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6400V2 Firmware by Netgear

Version Range Affected
To 1.0.4.98 (exclusive)
cpe:2.3:o:netgear:r6400v2_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ac2400 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:ac2400_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6220 Firmware by Netgear

Version Range Affected
To 1.1.0.100 (exclusive)
cpe:2.3:o:netgear:r6220_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Cbk40 Firmware by Netgear

Version Range Affected
To 2.5.0.10 (exclusive)
cpe:2.3:o:netgear:cbk40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6120 Firmware by Netgear

Version Range Affected
To 1.0.0.70 (exclusive)
cpe:2.3:o:netgear:r6120_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax80 Firmware by Netgear

Version Range Affected
To 1.0.3.102 (exclusive)
cpe:2.3:o:netgear:rax80_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr10 Firmware by Netgear

Version Range Affected
To 2.6.1.44 (exclusive)
cpe:2.3:o:netgear:rbr10_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Xr700 Firmware by Netgear

Version Range Affected
To 1.0.1.34 (exclusive)
cpe:2.3:o:netgear:xr700_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rs400 Firmware by Netgear

Version Range Affected
To 1.5.0.48 (exclusive)
cpe:2.3:o:netgear:rs400_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6700V2 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r6700v2_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk12 Firmware by Netgear

Version Range Affected
To 2.6.1.44 (exclusive)
cpe:2.3:o:netgear:rbk12_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6350 Firmware by Netgear

Version Range Affected
To 1.1.0.76 (exclusive)
cpe:2.3:o:netgear:r6350_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk50 Firmware by Netgear

Version Range Affected
To 2.6.1.40 (exclusive)
cpe:2.3:o:netgear:rbk50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbs40 Firmware by Netgear

Version Range Affected
To 2.6.1.38 (exclusive)
cpe:2.3:o:netgear:rbs40_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax50 Firmware by Netgear

Version Range Affected
To 1.0.2.64 (exclusive)
cpe:2.3:o:netgear:rax50_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

D7800 Firmware by Netgear

Version Range Affected
To 1.0.1.58 (exclusive)
cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax75 Firmware by Netgear

Version Range Affected
To 1.0.3.102 (exclusive)
cpe:2.3:o:netgear:rax75_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6900 Firmware by Netgear

Version Range Affected
To 1.0.2.16 (exclusive)
cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7350 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r7350_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex7500 Firmware by Netgear

Version Range Affected
To 1.0.0.68 (exclusive)
cpe:2.3:o:netgear:ex7500_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk852 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbk852_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax120 Firmware by Netgear

Version Range Affected
To 1.0.1.136 (exclusive)
cpe:2.3:o:netgear:rax120_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6800 Firmware by Netgear

Version Range Affected
To 1.2.0.72 (exclusive)
cpe:2.3:o:netgear:r6800_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7800 Firmware by Netgear

Version Range Affected
To 1.0.2.74 (exclusive)
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Eax80 Firmware by Netgear

Version Range Affected
To 1.0.1.62 (exclusive)
cpe:2.3:o:netgear:eax80_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr20 Firmware by Netgear

Version Range Affected
To 2.6.1.36 (exclusive)
cpe:2.3:o:netgear:rbr20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rax15 Firmware by Netgear

Version Range Affected
To 1.0.1.64 (exclusive)
cpe:2.3:o:netgear:rax15_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7000 Firmware by Netgear

Version Range Affected
To 1.0.11.106 (exclusive)
cpe:2.3:o:netgear:r7000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Xr300 Firmware by Netgear

Version Range Affected
To 1.0.3.50 (exclusive)
cpe:2.3:o:netgear:xr300_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Mk62 Firmware by Netgear

Version Range Affected
To 1.0.5.102 (exclusive)
cpe:2.3:o:netgear:mk62_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7900 Firmware by Netgear

Version Range Affected
To 1.0.4.26 (exclusive)
cpe:2.3:o:netgear:r7900_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R6700V3 Firmware by Netgear

Version Range Affected
To 1.0.4.98 (exclusive)
cpe:2.3:o:netgear:r6700v3_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk20 Firmware by Netgear

Version Range Affected
To 2.6.1.38 (exclusive)
cpe:2.3:o:netgear:rbk20_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R7960P Firmware by Netgear

Version Range Affected
To 1.4.1.62 (exclusive)
cpe:2.3:o:netgear:r7960p_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

R8000 Firmware by Netgear

Version Range Affected
To 1.0.4.58 (exclusive)
cpe:2.3:o:netgear:r8000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk842 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbk842_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbk752 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbk752_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rbr850 Firmware by Netgear

Version Range Affected
To 3.2.16.6 (exclusive)
cpe:2.3:o:netgear:rbr850_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://kb.netgear.com/000062735/Security-Advisory-for-Pre-Authentication-Buffe…
https://kb.netgear.com/000062735/Security-Advisory-for-Pre-Authentication-Buffe…