Netgear has fixed a high-severity vulnerability affecting multiple WiFi router models and advised customers to update their devices to the latest available firmware as soon as possible. The flaw impacts multiple Wireless AC Nighthawk, Wireless AX Nighthawk (WiFi 6), and Wireless AC router models.
Netgear has not released any details on what mechanism(s) allow the abuse of this flaw, just that the vulnerability is a pre-authentication buffer overflow vulnerability. Buffer overflows can lead to denial-of-service, arbitrary command execution, and other malicious activity.
The affected devices and patched firmware versions are as follows:
Vulnerable Netgear router | Patched firmware version |
RAX40 | Firmware version 1.0.2.60 |
RAX35 | Firmware version 1.0.2.60 |
R6400v2 | Firmware version 1.0.4.122 |
R6700v3 | Firmware version 1.0.4.122 |
R6900P | Firmware version 1.3.3.152 |
R7000P | Firmware version 1.3.3.152 |
R7000P | Firmware version 1.0.11.136 |
R7960P | Firmware version 1.4.4.94 |
R8000P | Firmware version 1.4.4.94 |