CVE-2020-15636

CRITICAL

NETGEAR R6700 Firmware < 1.0.4.98 - Unauthenticated Stack-based Buffer Overflow via RAE_Policy.json raePolicyVersion

Title source: llm
STIX 2.1

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900, R8000, RS400, and XR300 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific flaw exists within the check_ra service. A crafted raePolicyVersion in a RAE_Policy.json file can trigger an overflow of a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9852.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.1981
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-121
Status published
Products (1)
netgear/r6700_firmware < 1.0.4.98
Published Aug 20, 2020
Tracked Since Feb 18, 2026