CVE-2017-18704: Infoleak
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.16, R6300v2 before 1.0.4.18, R6400 before 1.01.32, R6400v2 before 1.0.2.44, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R7000 before 1.0.9.14, R7000P before 1.3.0.8, R6900P before 1.3.0.8, R7100LG before 1.0.0.34, R7300DST before 1.0.0.56, R7900 before 1.0.1.26, R8000 before 1.0.4.4, R8500 before 1.0.2.106, R8300 before 1.0.2.106, and WNDR3400v3 before 1.0.1.16.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2017-18704?
D6220 (before 1.0.0.32), D6400 (before 1.0.0.60), D8500 (before 1.0.3.29), R6250 (before 1.0.4.16), R6300v2 (before 1.0.4.18), R6400 (before 1.01.32), R6400v2 (before 1.0.2.44), R6700 (before 1.0.1.36), R6900 (before 1.0.1.34), R7000 (before 1.0.9.14), R7000p (before 1.3.0.8), R6900p (before 1.3.0.8), R7100lg (before 1.0.0.34), R7300dst (before 1.0.0.56), R7900 (before 1.0.1.26), R8000 (before 1.0.4.4), R8500 (before 1.0.2.106), R8300 (before 1.0.2.106), Wndr3400 (before 1.0.1.16)
What is the severity of CVE-2017-18704?
The severity of CVE-2017-18704 is medium, with a CVSS score of 6.5.
How can an attacker exploit CVE-2017-18704?
An attacker can exploit CVE-2017-18704 by gaining the ability to read arbitrary files on the affected NETGEAR devices.
How can I fix CVE-2017-18704?
To fix CVE-2017-18704, update the firmware of the affected NETGEAR devices to the latest version available.
Where can I find more information about CVE-2017-18704?
You can find more information about CVE-2017-18704 in the Netgear security advisory: https://kb.netgear.com/000053198/Security-Advisory-for-Arbitrary-File-Read-on-Some-Routers-and-Gateways-PSV-2017-0590