CVE-2024-50996

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*

History

07 May 2025, 15:25

Type Values Removed Values Added
First Time Netgear r7000p
Netgear r6400v2
Netgear r7000p Firmware
Netgear xr300 Firmware
Netgear xr300
Netgear r6400v2 Firmware
Netgear r8500
Netgear
Netgear r8500 Firmware
References () https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_37/37.md - () https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_37/37.md - Broken Link
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory
CPE cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*
cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*

Information

Published : 2024-11-05 15:15

Updated : 2025-05-07 15:25


NVD link : CVE-2024-50996

Mitre link : CVE-2024-50996

CVE.ORG link : CVE-2024-50996


JSON object : View

Products Affected

netgear

  • r7000p_firmware
  • r7000p
  • xr300
  • r6400v2
  • r8500
  • xr300_firmware
  • r6400v2_firmware
  • r8500_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')