9.8
CVSSv3

CVE-2021-45608

Published: 26/12/2021 Updated: 29/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Certain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated attacker. Remote code execution from the WAN interface (TCP port 20005) cannot be ruled out; however, exploitability was judged to be of "rather significant complexity" but not "impossible." The overflow is in SoftwareBus_dispatchNormalEPMsgOut in the KCodes NetUSB kernel module. Affected NETGEAR devices are D7800 prior to 1.0.1.68, R6400v2 prior to 1.0.4.122, and R6700v3 prior to 1.0.4.122.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgear d7800_firmware

netgear r6400v2_firmware

netgear r6700v3_firmware