Impact
A buffer overflow in the specified NETGEAR routers permits a device administrator to cause a temporary interruption of the device’s normal operation. The primary impact is a denial‑of‑service condition, with no evidence in the description of confidentiality or integrity compromise. Based on the wording, the overflow would be triggered by a privileged user or a service running with administrative rights on the device.
Affected Systems
Affected models include NETGEAR RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX49S, RAX50, RAX50v2, RAX54S, and RAX54Sv2. All impacted devices can be upgraded to firmware version V1.1.6.36, which contains the fix. Devices marked as End‑of‑Support (EoS) such as RAX41, RAX42, and RAX43 will not receive security updates and are recommended for retirement.
Risk and Exploitability
The CVSS score of 1.1 reflects very low severity, and no EPSS score is available, indicating that the exploitation probability is currently unquantified but considered low. The vulnerability is not listed in the CISA KEV catalog. Likely attacker scenarios involve a user with administrative access to the router management interface, potentially via a local network or a compromised management service.
OpenCVE Enrichment