CVE-2018-21170
Description
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stack-based buffer overflow in multiple NETGEAR devices allows unauthenticated attacker to execute arbitrary code.
Vulnerability
A stack-based buffer overflow vulnerability exists in the firmware of several NETGEAR devices, including EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56 [1]. The vulnerability is present in the pre-authentication code path, allowing an unauthenticated attacker to trigger the overflow without any credentials [1].
Exploitation
An unauthenticated attacker on the same network (adjacent) can send a specially crafted packet to the vulnerable device, causing a stack-based buffer overflow [1]. The CVSS vector indicates low attack complexity and no user interaction required (AV:A/AC:L/PR:N/UI:N) [1]. The attacker does not need any prior authentication or access to the device.
Impact
Successful exploitation allows the attacker to achieve arbitrary code execution on the device, potentially gaining full control [1]. The CVSS score of 8.8 (High) reflects high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) [1].
Mitigation
NETGEAR has released firmware updates to fix the vulnerability: EX2700 version 1.0.1.28, R7800 version 1.0.2.40, WN2000RPTv3 version 1.0.1.20, WN3000RPv3 version 1.0.2.50, and WN3100RPv2 version 1.0.0.56 [1]. Users should download and install the latest firmware from NETGEAR Support. There is no workaround; updating the firmware is the only mitigation [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/devicesdescription
- Range: <1.0.1.20
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.