Vulnerability Details CVE-2018-21203
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6100 before 1.0.1.20, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 5.8
Products affected by CVE-2018-21203
-
cpe:2.3:h:netgear:r6100:-
-
cpe:2.3:h:netgear:r9000:-
-
cpe:2.3:h:netgear:wndr3700:v4
-
cpe:2.3:h:netgear:wndr4300:-
-
cpe:2.3:h:netgear:wndr4300:v2
-
cpe:2.3:h:netgear:wndr4500:v3
-
cpe:2.3:o:netgear:r6100_firmware:-
-
cpe:2.3:o:netgear:r6100_firmware:1.0.1.1
-
cpe:2.3:o:netgear:r6100_firmware:1.0.1.12
-
cpe:2.3:o:netgear:r6100_firmware:1.0.1.14
-
cpe:2.3:o:netgear:r6100_firmware:1.0.1.16
-
cpe:2.3:o:netgear:r9000_firmware:-
-
cpe:2.3:o:netgear:r9000_firmware:1.0.2.30
-
cpe:2.3:o:netgear:r9000_firmware:1.0.2.4
-
cpe:2.3:o:netgear:r9000_firmware:1.0.2.40
-
cpe:2.3:o:netgear:wndr3700_firmware:-
-
cpe:2.3:o:netgear:wndr3700_firmware:1.0.1.14
-
cpe:2.3:o:netgear:wndr3700_firmware:1.0.2.86
-
cpe:2.3:o:netgear:wndr3700_firmware:1.0.2.88
-
cpe:2.3:o:netgear:wndr3700_firmware:1.0.2.92
-
cpe:2.3:o:netgear:wndr3700_firmware:1.0.2.94
-
cpe:2.3:o:netgear:wndr4300_firmware:-
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.0.48
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.0.50
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.0.52
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.0.54
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.0.56
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.0.58
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.2.88
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.2.90
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.2.92
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.2.94
-
cpe:2.3:o:netgear:wndr4300_firmware:1.0.2.96
-
cpe:2.3:o:netgear:wndr4500_firmware:-
-
cpe:2.3:o:netgear:wndr4500_firmware:1.0.0.48