NETGEAR Orbi WiFi 6 and 6E Systems Buffer Vulnerability Allowing Unauthorized Software Modifications by Authenticated Administrators
Vulnerability
A vulnerability exists in certain NETGEAR Orbi WiFi 6 and 6E systems, specifically in the RBE372, RBE770, RBR750, RBR840, RBR850, RBRE950, RBRE960, RBS750, RBS840, and RBS860 models. This vulnerability stems from inadequate input validation of buffers, which enables authenticated administrators on the local network to make unauthorized changes to the router's software and functionality.
Impact
Exploitation of this vulnerability could lead to unauthorized modifications of the router's software and features, potentially allowing for further malicious actions or disruptions.
Remediation
Users can update their devices to the latest firmware version, 7.2.8.5 for the RBR750, RBR840, RBR850, RBRE950, RBRE960, RBS750, RBS840, and RBS860 models, and 12.1.3.12 for the RBE372 and RBE770 models. The firmware can be downloaded from the NETGEAR Download Center.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
