CVE-2019-20748
published 2020-04-16CVE-2019-20748: Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38…
PriorityP429medium6.8CVSS 3.1
AVAACLPRHUINSUCHIHAH
EPSS
0.51%
39.8th percentile
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, and RBS50 before 2.3.0.32.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | d7800_firmware | < 1.0.1.44 | 1.0.1.44 |
| netgear | r7500_firmware | < 1.0.3.38 | 1.0.3.38 |
| netgear | r7800_firmware | < 1.0.2.52 | 1.0.2.52 |
| netgear | rbk20_firmware | < 2.3.0.28 | 2.3.0.28 |
| netgear | rbk40_firmware | < 2.3.0.28 | 2.3.0.28 |
| netgear | rbk50_firmware | < 2.3.0.32 | 2.3.0.32 |
| netgear | rbr20_firmware | < 2.3.0.28 | 2.3.0.28 |
| netgear | rbr50_firmware | < 2.3.0.32 | 2.3.0.32 |
| netgear | rbs20_firmware | < 2.3.0.28 | 2.3.0.28 |
| netgear | rbs40_firmware | < 2.3.0.28 | 2.3.0.28 |
| netgear | rbs50_firmware | < 2.3.0.32 | 2.3.0.32 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.8MEDIUMCVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43g3-9hv3-rp7w: Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user
ghsa_unreviewed·2022-05-24
CVE-2019-20748 [MEDIUM] GHSA-43g3-9hv3-rp7w: Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, and RBS50 before 2.3.0.32.
OSV
italc vulnerabilities
osv·2020-09-28·CVSS 9.8
CVE-2019-15681 italc vulnerabilities
italc vulnerabilities
It was discovered that an information disclosure vulnerability existed in the
LibVNCServer vendored in iTALC when sending a ServerCutText message. An
attacker could possibly use this issue to expose sensitive information.
(CVE-2019-15681)
It was discovered that the LibVNCServer and LibVNCClient vendored in iTALC
incorrectly handled certain packet lengths. A remote attacker could possibly
use this issue to obtain sensitive information, cause a denial of service, or
execute arbitrary code.
(CVE-2018-15127 CVE-2018-20019, CVE-2018-20020, CVE-2018-20021, CVE-2018-20022,
CVE-2018-20023, CVE-2018-20024, CVE-2018-20748, CVE-2018-20749, CVE-2018-20750,
CVE-2018-7225, CVE-2019-15681)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-16
Published