VYPR
Unrated severityNVD Advisory· Published Apr 28, 2020· Updated Aug 5, 2024

CVE-2018-21203

CVE-2018-21203

Description

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6100 before 1.0.1.20, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack-based buffer overflow in several NETGEAR routers allows unauthenticated, adjacent attackers to achieve remote code execution.

Vulnerability

A stack-based buffer overflow vulnerability exists in the pre-authentication processing of several NETGEAR routers [1]. Affected devices include the R6100 before firmware version 1.0.1.20, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50 [1]. The vulnerability can be triggered over the network without any prior authentication.

Exploitation

An unauthenticated attacker with adjacent network access can send a specially crafted packet to the affected router to trigger the stack-based buffer overflow [1]. The CVSS v3 vector (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that no authentication or user interaction is required, and the attack complexity is low [1].

Impact

Successful exploitation allows an attacker to achieve a full compromise of confidentiality, integrity, and availability, potentially leading to remote code execution on the affected device [1]. The CVSS score of 8.8 (High) reflects this critical impact.

Mitigation

NETGEAR has released fixed firmware versions for all affected models: R6100 1.0.1.20, R9000 1.0.2.52, WNDR3700v4 1.0.2.96, WNDR4300 1.0.2.98, WNDR4300v2 1.0.0.50, and WNDR4500v3 1.0.0.50 [1]. Users should update their device firmware immediately. There is no known workaround; the only mitigation is to apply the available patches [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.