VYPR
Unrated severityNVD Advisory· Published Apr 27, 2020· Updated Aug 5, 2024

CVE-2018-21170

CVE-2018-21170

Description

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in multiple NETGEAR devices allows unauthenticated attacker to execute arbitrary code.

Vulnerability

A stack-based buffer overflow vulnerability exists in the firmware of several NETGEAR devices, including EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56 [1]. The vulnerability is present in the pre-authentication code path, allowing an unauthenticated attacker to trigger the overflow without any credentials [1].

Exploitation

An unauthenticated attacker on the same network (adjacent) can send a specially crafted packet to the vulnerable device, causing a stack-based buffer overflow [1]. The CVSS vector indicates low attack complexity and no user interaction required (AV:A/AC:L/PR:N/UI:N) [1]. The attacker does not need any prior authentication or access to the device.

Impact

Successful exploitation allows the attacker to achieve arbitrary code execution on the device, potentially gaining full control [1]. The CVSS score of 8.8 (High) reflects high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) [1].

Mitigation

NETGEAR has released firmware updates to fix the vulnerability: EX2700 version 1.0.1.28, R7800 version 1.0.2.40, WN2000RPTv3 version 1.0.1.20, WN3000RPv3 version 1.0.2.50, and WN3100RPv2 version 1.0.0.56 [1]. Users should download and install the latest firmware from NETGEAR Support. There is no workaround; updating the firmware is the only mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.