First published: Fri Apr 24 2020(Updated: )
Certain NETGEAR devices are affected by reflected XSS. This affects EX3700 before 1.0.0.66, EX3800 before 1.0.0.66, EX6100 before 1.0.2.20, EX6120 before 1.0.0.34, EX6150 before 1.0.0.36, EX6200 before 1.0.3.84, and EX7000 before 1.0.0.60.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Ex3700 Firmware | <1.0.0.66 | |
Netgear EX3700 | ||
Netgear Ex3800 Firmware | <1.0.0.66 | |
Netgear Ex3800 | ||
Netgear Ex6100 Firmware | <1.0.2.20 | |
Netgear EX6100 | ||
Netgear Ex6120 Firmware | <1.0.0.34 | |
Netgear EX6120 | ||
Netgear Ex6150 Firmware | <1.0.0.36 | |
Netgear Ex6150 | ||
Netgear Ex6200 Firmware | <1.0.3.84 | |
Netgear EX6200 | ||
Netgear Ex7000 Firmware | <1.0.0.60 | |
NETGEAR EX7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18715 is a vulnerability that affects certain NETGEAR devices and allows for reflected cross-site scripting (XSS) attacks.
CVE-2017-18715 affects the following NETGEAR devices: EX3700 before 1.0.0.66, EX3800 before 1.0.0.66, EX6100 before 1.0.2.20, EX6120 before 1.0.0.34, EX6150 before 1.0.0.36, EX6200 before 1.0.3.84, and EX7000 before 1.0.0.60.
CVE-2017-18715 has a severity of 6.1 (medium).
CVE-2017-18715 allows an attacker to execute malicious scripts in the victim's browser by tricking them into clicking on a specially crafted link.
To fix CVE-2017-18715, it is recommended to update the firmware of the affected NETGEAR devices to the latest version provided by the manufacturer.