CVE-2024-51003

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*

History

07 May 2025, 15:24

Type Values Removed Values Added
CPE cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*
cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*
References () https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_49/49.md - () https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_49/49.md - Broken Link
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory
Summary
  • (es) Se descubrieron múltiples vulnerabilidades de desbordamiento de pila en el componente ap_mode.cgi a través de los parámetros apmode_dns1_pri y apmode_dns1_sec en Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154 y R6400 v2 1.0.4.128. Estas vulnerabilidades permiten a los atacantes provocar una denegación de servicio (DoS) a través de una solicitud POST manipulada.
First Time Netgear xr300
Netgear r6400v2
Netgear r8500 Firmware
Netgear r6400v2 Firmware
Netgear
Netgear r7000p
Netgear r8500
Netgear xr300 Firmware
Netgear r7000p Firmware

05 Nov 2024, 16:35

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7

05 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-05 15:15

Updated : 2025-05-07 15:24


NVD link : CVE-2024-51003

Mitre link : CVE-2024-51003

CVE.ORG link : CVE-2024-51003


JSON object : View

Products Affected

netgear

  • r8500_firmware
  • xr300_firmware
  • r8500
  • r7000p_firmware
  • r6400v2
  • r6400v2_firmware
  • r7000p
  • xr300
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')