Impact
A stack-based buffer overflow (CWE‑787) was identified in several NETGEAR Nighthawk routers, also involving improper input validation (CWE‑20). The flaw allows an authenticated administrator to overwrite memory on the router’s stack, enabling unauthorized modification of router software or configuration. This could compromise the integrity of the device, leading to unintended routing policies, loss of network isolation, or deployment of malicious firmware.
Affected Systems
The affected products are NETGEAR Nighthawk routers, including models RAX20, RAX35v2, RAX41, RAX41v2, RAX42, RAX42v2, RAX43, RAX43v2, RAX45, RAX49S, RAX50, RAX50S, RAX50v2, RAX54Sv2, RAX54v2, RAXE450, RAXE500, XR1000, and XR1000v2. Firmware versions susceptible to the vulnerability include V1.0.16.132 and V1.1.4.28, along with earlier builds. Devices marked End‑of‑Support (EoS) such as RAX20, RAX41, RAX42, and RAX45 have ceased receiving security updates, and users are advised to retire or replace them with newer, supported models.
Risk and Exploitability
With a CVSS score of 1.9 and an EPSS score of less than 1 %, the vulnerability is assessed as low severity and with a very low probability of exploitation. Attackers require authenticated administrative credentials to trigger the stack overflow, limiting the risk to devices already accessed by the attacker. The CISA KEV catalog does not list this CVE, and no publicly confirmed exploitation has been reported. Nonetheless, any compromised administrative session could allow unauthorized firmware changes, so prompt patching and strong credential protection remain important.
OpenCVE Enrichment