CVE-2024-52013

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*

History

21 May 2025, 20:24

Type Values Removed Values Added
Summary
  • (es) Se descubrió que Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154 y R6400 v2 1.0.4.128 contenían un desbordamiento de pila a través del parámetro pptp_user_ip en wiz_pptp.cgi. Esta vulnerabilidad permite a los atacantes provocar una denegación de servicio (DoS) a través de una solicitud POST manipulada.
First Time Netgear r7000p Firmware
Netgear r8500 Firmware
Netgear r8500
Netgear xr300
Netgear
Netgear r6400v2
Netgear r7000p
Netgear r6400v2 Firmware
Netgear xr300 Firmware
CPE cpe:2.3:h:netgear:r7000p:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6400v2_firmware:1.0.4.128:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r8500_firmware:1.0.2.160:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r8500:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7000p_firmware:1.3.3.154:*:*:*:*:*:*:*
cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr300:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6400v2:-:*:*:*:*:*:*:*
References () https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_43/43.md - () https://github.com/wudipjq/my_vuln/blob/main/Netgear4/vuln_43/43.md - Broken Link
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory

05 Nov 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7
CWE CWE-120

05 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-05 15:15

Updated : 2025-05-21 20:24


NVD link : CVE-2024-52013

Mitre link : CVE-2024-52013

CVE.ORG link : CVE-2024-52013


JSON object : View

Products Affected

netgear

  • r7000p
  • xr300
  • r6400v2
  • r7000p_firmware
  • r8500
  • xr300_firmware
  • r8500_firmware
  • r6400v2_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')