Impact
The vulnerability is a stack overflow in the firmware of specific NETGEAR Orbi routers that leads to a denial of service, allowing an unauthorized user to cause the device to become unresponsive or reboot, disrupting network connectivity and temporarily denying access to the device.
Affected Systems
Affected devices include the NETGEAR Orbi RBE970, RBE971, RBR860, RBRE950, RBRE960, RBS860, RBSE950, and RBSE960 models. The flaw was present in the default firmware before version V9.10.1.4 for the RBE970 and RBE971, and before V7.2.7.15 for the RBR860, RBRE950, RBRE960, RBS860, RBSE950, and RBSE960. Firmware updates to these listed versions contain a patch that resolves the stack overflow.
Risk and Exploitability
The CVSS score is 5.7, indicating moderate severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network-based, where an attacker with network access can trigger the stack overflow, potentially by sending malformed packets to the affected service. No additional prerequisites are mentioned, and the flaw can be exploited remotely if the network is not securely segmented.
OpenCVE Enrichment