Impact
A buffer‑overflow flaw (CWE‑119) in Netgear Orbi 370 series routers allows an attacker who can intercept and modify traffic between the router and the Internet to execute commands on the device when the local administrator performs specific management actions. The vulnerability enables the attacker to gain administrative control, modify configuration, install malware, or disrupt network operations.
Affected Systems
Devices in the Orbi 370 series – models RBE370, RBE371, RBE372, and RBE374 – running firmware versions earlier than V12.1.2.7 are affected.
Risk and Exploitability
The base CVSS score of 4.8 indicates moderate severity, and the EPSS score is unavailable, so the likelihood of exploitation is unknown. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to have the ability to tamper with traffic between the router and the Internet and to trigger management actions on the device, making widespread exploitation less likely. However, a successful exploit would provide full administrative authority over the router.
OpenCVE Enrichment