High severity7.8NVD Advisory· Published Mar 18, 2022· Updated Jun 17, 2026
CVE-2022-24655
CVE-2022-24655
Description
A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- cpe:2.3:o:netgear:cax80_firmware:2.1.2.6:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:dc112a_firmware:1.0.0.62:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:ex6100_firmware:201.0.2.28:*:*:*:*:*:*:*
- cpe:2.3:o:netgear:ex6200_firmware:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/doudoudedi/Netgear_product_stack_overflow/blob/main/NETGEAR%20EX%20series%20upnpd%20stack_overflow.mdnvdExploitPatchThird Party Advisory
- kb.netgear.com/000064615/Security-Advisory-for-Pre-Authentication-Command-Injection-on-EX6100v1-and-Pre-Authentication-Stack-Overflow-on-Multiple-Products-PSV-2021-0282-PSV-2021-0288nvdVendor Advisory
- www.netgear.com/about/security/nvdVendor Advisory
News mentions
0No linked articles in our index yet.