CVE-2018-21148
Description
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated users can trigger a stack-based buffer overflow on multiple NETGEAR devices, leading to potential arbitrary code execution.
Vulnerability
A stack-based buffer overflow vulnerability exists in the firmware of multiple NETGEAR routers and gateways. The flaw is triggered when an authenticated user sends crafted input to a specific service or handler, causing the stack to overflow. Affected models include D7800 (before 1.0.1.34), DM200 (before 1.0.0.50), R6100 (before 1.0.1.22), R7500 (before 1.0.0.122), R7500v2 (before 1.0.3.26), R7800 (before 1.0.2.42), R8900 (before 1.0.3.10), R9000 (before 1.0.3.10), WNDR3700v4 (before 1.0.2.96), WNDR4300 (before 1.0.2.98), WNDR4300v2 (before 1.0.0.54), WNDR4500v3 (before 1.0.0.54), and WNR2000v5 (before 1.0.0.64) [1].
Exploitation
An attacker must first authenticate to the device. Once authenticated, the attacker can send specially crafted data (likely via a web interface or a management protocol) that exploits the stack overflow. The exact steps are not detailed in the available references, but the vulnerability is reachable after authentication is established [1].
Impact
Successful exploitation of the stack overflow may allow the attacker to crash the device (denial of service) or potentially achieve arbitrary code execution with elevated privileges, compromising the confidentiality, integrity, and availability of the device. The advisory does not provide deeper technical details on the privilege level obtained, but the impact is considered serious due to the widespread use of these devices in network environments [1].
Mitigation
NETGEAR has released firmware updates for all affected models. Users should update their devices to the latest firmware version as specified: D7800 to 1.0.1.34, DM200 to 1.0.0.50, R6100 to 1.0.1.22, R7500 to 1.0.0.122, R7500v2 to 1.0.3.26, R7800 to 1.0.2.42, R8900 to 1.0.3.10, R9000 to 1.0.3.10, WNDR3700v4 to 1.0.2.96, WNDR4300 to 1.0.2.98, WNDR4300v2 to 1.0.0.54, WNDR4500v3 to 1.0.0.54, and WNR2000v5 to 1.0.0.64. Firmware files are available via the NETGEAR Support website [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/devicesdescription
- Range: <1.0.0.50
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.