CVE-2022-24655Out-of-bounds Write in Netgear Cax80 Firmware

Severity
7.8HIGHNVD
EPSS
0.1%
top 65.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMar 19

Description

A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j626-6whp-pj3p: A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 2012022-03-19
CVEList
CVE-2022-24655: A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 2012022-03-18
CVE-2022-24655 — Out-of-bounds Write in Netgear | cvebase