CVE-2021-38526

Severity
7.5HIGH
EPSS
0.3%
top 48.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX35 before 1.0.3.94, RAX38 before 1.0.3.94, and RAX40 before 1.0.3.94.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDnetgear/rax35_firmware< 1.0.3.94
NVDnetgear/rax38_firmware< 1.0.3.94
NVDnetgear/rax40_firmware< 1.0.3.94

🔴Vulnerability Details

2
GHSA
GHSA-w6cx-mcrx-5955: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker2022-05-24
CVEList
CVE-2021-38526: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker2021-08-11
CVE-2021-38526 (HIGH CVSS 7.5) | Certain NETGEAR devices are affecte | cvebase.io