CVE-2020-28373 - CVE House
Back to Database
Status published High CVE-2020-28373

upnpd on certain NETGEAR devices allows remote (LAN) attackers to...

Vulnerability Description

upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overflow. This affects R6400v2 V1.0.4.102_10.0.75, R6400 V1.0.1.62_1.0.41, R7000P V1.3.2.126_10.1.66, XR300 V1.0.3.50_10.3.36, R8000 V1.0.4.62, R8300 V1.0.2.136, R8500 V1.0.2.136, R7300DST V1.0.0.74, R7850 V1.0.5.64, R7900 V1.0.4.30, RAX20 V1.0.2.64, RAX80 V1.0.3.102, and R6250 V1.0.4.44.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28373

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

r6400v2 firmware, r6400 firmware, r7000p firmware, xr300 firmware, r8000 firmware, r8300 firmware, r8500 firmware, r7300dst firmware, r7850 firmware, r7900 firmware, rax20 firmware, rax80 firmware, r6250 firmware
Vulnerable Versions:
1.0.4.102_10.0.75, 1.0.1.62_1.0.41, 1.3.2.126_10.1.66, 1.0.3.50_10.3.36, 1.0.4.62, 1.0.2.136, 1.0.0.74, 1.0.5.64, 1.0.4.30, 1.0.2.64, 1.0.3.102, 1.0.4.44

Timeline

Official Publish: November 9th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.