VYPR
Unrated severityNVD Advisory· Published Apr 16, 2020· Updated Aug 5, 2024

CVE-2019-20753

CVE-2019-20753

Description

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects DGN2200v1 before 1.0.0.58, D8500 before 1.0.3.42, D7000v2 before 1.0.0.51, D6400 before 1.0.0.78, D6220 before 1.0.0.44, JNDR3000 before 1.0.0.24, R8000 before 1.0.4.18, R8500 before 1.0.2.122, R8300 before 1.0.2.122, R7900 before 1.0.2.16, R7000P before 1.3.2.34, R7300DST before 1.0.0.68, R7100LG before 1.0.0.46, R6900P before 1.3.2.34, R7000 before 1.0.9.28, R6900 before 1.0.1.46, R6700 before 1.0.1.46, R6400v2 before 1.0.2.56, R6400 before 1.0.1.42, R6300v2 before 1.0.4.28, R6250 before 1.0.4.26, WNDR3400v3 before 1.0.1.22, WNDR4500v2 before 1.0.0.72, and WNR3500Lv2 before 1.2.0.50.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in multiple NETGEAR devices allows unauthenticated remote attackers to execute arbitrary code via a specially crafted request.

Vulnerability

A stack-based buffer overflow vulnerability exists in the pre-authentication code path of several NETGEAR routers and modem routers. The bug can be triggered by a remote unauthenticated attacker through a specially crafted request. Affected devices and firmware versions include: DGN2200v1 before 1.0.0.58, D8500 before 1.0.3.42, D7000v2 before 1.0.0.51, D6400 before 1.0.0.78, D6220 before 1.0.0.44, JNDR3000 before 1.0.0.24, R8000 before 1.0.4.18, R8500 before 1.0.2.122, R8300 before 1.0.2.122, R7900 before 1.0.2.16, R7000P before 1.3.2.34, R7300DST before 1.0.0.68, R7100LG before 1.0.0.46, R6900P before 1.3.2.34, R7000 before 1.0.9.28, R6900 before 1.0.1.46, R6700 before 1.0.1.46, R6400v2 before 1.0.2.56, R6400 before 1.0.1.42, R6300v2 before 1.0.4.28, R6250 before 1.0.4.26, WNDR3400v3 before 1.0.1.22, WNDR4500v2 before 1.0.0.72, and WNR3500Lv2 before 1.2.0.50 [1].

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending a crafted network request to the affected device. No prior authentication or user interaction is required. The overflow occurs in a stack buffer during processing of the request, allowing the attacker to overwrite adjacent memory.

Impact

Successful exploitation could allow the attacker to execute arbitrary code on the device with elevated privileges. This could lead to full compromise of the device, including the ability to install malware, intercept network traffic, or pivot to other devices on the network. The vulnerability is classified as a stack overflow in a pre-authentication service, making it particularly dangerous for devices exposed to the internet.

Mitigation

NETGEAR has released firmware updates to address this vulnerability. Users should upgrade to the fixed firmware version for their specific device as listed in the advisory [1]. As of the publication date, no workaround is available, and the vendor strongly recommends applying the latest firmware. Devices that have reached end-of-life (EOL) may not receive updates and should be replaced.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.