CVE Feed

    Dashboard / CVE / CVE-2021-45608

    CVE-2021-45608

    Certain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated attacker. Remote code execution from the WAN interface (TCP port 20005) cannot be ruled out; however, exploitability was judged to be of "rather significant complexity" but not "impossible." The overflow is in SoftwareBus_dispatchNormalEPMsgOut in the KCodes NetUSB kernel module. Affected NETGEAR devices are D7800 before 1.0.1.68, R6400v2 before 1.0.4.122, and R6700v3 before 1.0.4.122.

    Published:Dec 26, 2021
    Last Modified:Nov 21, 2024
    EPS:Dec 26, 2021
    EPSS Score:0.05212
    CVSS Score:6.5

    Affected Products

    Vendor
    Netgear
    Product
    D7800
    Vendor
    Netgear
    Product
    D7800 Firmware
    Vendor
    Netgear
    Product
    R6400v2
    Vendor
    Netgear
    Product
    R6400v2 Firmware
    Vendor
    Netgear
    Product
    R6700v3
    Vendor
    Netgear
    Product
    R6700v3 Firmware

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High