Netgear EX6200 Buffer Overflow Vulnerability in Function sub_3D0BC

Vulnerability

A critical buffer overflow vulnerability has been identified in the Netgear EX6200 router, specifically in version 1.0.3.94. The issue arises in the function sub_3D0BC, where the host argument is manipulated, leading to a buffer overflow. This vulnerability can be exploited remotely, and while the technical details of the exploitation are known, no public exploit is currently available.

Impact

Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a denial-of-service condition on the device.

Reproduction

The vulnerability can be reproduced by sending a crafted request that manipulates the 'host' argument. The lack of input validation in the 'strcpy' function used within 'sub_3D0BC' creates the buffer overflow condition.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.