Netgear Products Multiple Vulnerabilities
Last Update Date:
5 Mar 2020 12:19
Release Date:
5 Mar 2020
5422
Views
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities were identified in Netgear products, a remote attacker could exploit some of these vulnerabilities to trigger remote code execution and security restriction bypass on the targeted system.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- D6220, running firmware versions prior to 1.0.0.52
- D6400, running firmware versions prior to 1.0.0.86
- D7000v2, running firmware versions prior to 1.0.0.53
- D8500, running firmware versions prior to 1.0.3.44
- R6220, running firmware versions prior to 1.1.0.80
- R6250, running firmware versions prior to 1.0.4.34
- R6260, running firmware versions prior to 1.1.0.64
- R6400, running firmware versions prior to 1.0.1.46
- R6400v2, running firmware versions prior to 1.0.2.66
- R6700, running firmware versions prior to 1.0.2.8
- R6700v2, running firmware versions prior to 1.2.0.36
- R6700v3, running firmware versions prior to 1.0.4.84
- R6800, running firmware versions prior to 1.2.0.36
- R6900, running firmware versions prior to 1.0.2.8
- R6900P, running firmware versions prior to 1.3.1.64
- R6900v2, running firmware versions prior to 1.2.0.36
- R7000, running firmware versions prior to 1.0.9.42
- R7000P, running firmware versions prior to 1.3.1.64
- R7100LG, running firmware versions prior to 1.0.0.50
- R7300DST, running firmware versions prior to 1.0.0.70
- R7800, running firmware versions prior to 1.0.2.60
- R7900, running firmware versions prior to 1.0.3.10
- R7900P, running firmware versions prior to 1.4.1.30
- R8000, running firmware versions prior to 1.0.4.28
- R8000P, running firmware versions prior to 1.4.1.30
- R8300, running firmware versions prior to 1.0.2.128
- R8500, running firmware versions prior to 1.0.2.128
- R8900, running firmware versions prior to 1.0.4.12
- R9000, running firmware versions prior to 1.0.4.12
- XR500, running firmware versions prior to 2.3.2.32
Solutions
Before installation of the software, please visit the vendor's web-site for more details.
- Apply fixes issued by the vendor:
https://www.netgear.com/support/
Vulnerability Identifier
- No CVE information is available
Source
Related Link
- https://kb.netgear.com/000061760/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Gateways-PSV-2018-0352
- https://kb.netgear.com/000061741/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-Routers-PSV-2019-0051
- https://kb.netgear.com/000061740/Security-Advisory-for-Unauthenticated-Remote-Code-Execution-on-R7800-PSV-2019-0076
Share with