VYPR
Unrated severityNVD Advisory· Published Apr 16, 2020· Updated Aug 5, 2024

CVE-2019-20712

CVE-2019-20712

Description

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R6250 before 1.0.4.34, R6300v2 before 1.0.4.32, R6400 before 1.0.1.46, R6400v2 before 1.0.2.62, R6700 before 1.0.2.6, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R7000 before 1.0.9.60, R7000P before 1.3.1.64, R7100LG before 1.0.0.52, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R7900P before 1.4.1.30, R8000 before 1.0.4.28, R8000P before 1.4.1.30, R8300 before 1.0.2.128, R8500 before 1.0.2.128, WNDR3400v3 before 1.0.1.24, and WNR3500Lv2 before 1.2.0.56.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in many NETGEAR routers and gateways allows authenticated users to cause undefined behavior; fixes are available.

Vulnerability

A buffer overflow vulnerability exists in the firmware of multiple NETGEAR routers and gateways. The issue is triggered post-authentication, meaning the attacker must first have valid credentials or access to the web interface. Affected devices include the D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R6250 before 1.0.4.34, R6300v2 before 1.0.4.32, R6400 before 1.0.1.46, R6400v2 before 1.0.2.62, R6700 before 1.0.2.6, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R7000 before 1.0.9.60, R7000P before 1.3.1.64, R7100LG before 1.0.0.52, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R7900P before 1.4.1.30, R8000 before 1.0.4.28, R8000P before 1.4.1.30, R8300 before 1.0.2.128, R8500 before 1.0.2.128, WNDR3400v3 before 1.0.1.24, and WNR3500Lv2 before 1.2.0.56. [1]

Exploitation

An attacker must be able to authenticate to the affected device's web interface. After obtaining valid login credentials, the attacker can send a crafted request that triggers a buffer overflow. The vendor advisory does not detail the exact input vector, but indicates that the overflow occurs post-authentication and is exploitable by an authenticated user. [1]

Impact

Successfully exploiting the buffer overflow could cause the device to crash or potentially allow arbitrary code execution. The advisory describes the impact as a buffer overflow but does not specify the exact outcome; however, such overflows often lead to denial of service or remote code execution with the privileges of the affected service. [1]

Mitigation

NETGEAR has released firmware updates to fix the vulnerability. Users should upgrade to the specified patched versions listed in the advisory. For example, the R7000 should be updated to firmware version 1.0.9.60 (or later), and the R7000P to 1.3.1.64 (or later). The fix is included in the latest firmware for each model as of the advisory date. No workaround is provided, and users are strongly encouraged to install the updates. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.