VYPR
Unrated severityNVD Advisory· Published Apr 28, 2020· Updated Aug 5, 2024

CVE-2018-21222

CVE-2018-21222

Description

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR routers and gateways are vulnerable to a pre-authentication buffer overflow, allowing unauthenticated attackers to execute arbitrary code.

Vulnerability

A pre-authentication buffer overflow vulnerability exists in several NETGEAR router and gateway models. The flaw occurs in the firmware's handling of network requests without requiring authentication. Affected devices include D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62 [1].

Exploitation

An unauthenticated attacker on the local network can send specially crafted packets to the vulnerable device during the pre-authentication phase, triggering a buffer overflow. No user interaction or credentials are required [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code on the device, potentially gaining full control over the router or gateway. This can lead to disclosure of sensitive information, modification of network traffic, and denial of service [1].

Mitigation

NETGEAR has released firmware updates that fix the vulnerability. Users should download and install the latest firmware for their respective models from the NETGEAR Support website [1]. No workarounds are mentioned; applying the firmware update is the only mitigation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.