CVE-2017-6862

CVE Published 2017-05-26
Related CWE(s) CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Related Vendor(s) netgear
Related Product(s) wnr2000v3_firmware, wnr2000v5_firmware, wnr2000v4_firmware
Exploitation Reported (CISA KEV) 2022-06-08
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References