CVE-2017-18715: XSS
Certain NETGEAR devices are affected by reflected XSS. This affects EX3700 before 1.0.0.66, EX3800 before 1.0.0.66, EX6100 before 1.0.2.20, EX6120 before 1.0.0.34, EX6150 before 1.0.0.36, EX6200 before 1.0.3.84, and EX7000 before 1.0.0.60.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18715?
CVE-2017-18715 is a vulnerability that affects certain NETGEAR devices and allows for reflected cross-site scripting (XSS) attacks.
Which NETGEAR devices are affected by CVE-2017-18715?
CVE-2017-18715 affects the following NETGEAR devices: EX3700 before 1.0.0.66, EX3800 before 1.0.0.66, EX6100 before 1.0.2.20, EX6120 before 1.0.0.34, EX6150 before 1.0.0.36, EX6200 before 1.0.3.84, and EX7000 before 1.0.0.60.
What is the severity of CVE-2017-18715?
CVE-2017-18715 has a severity of 6.1 (medium).
How does CVE-2017-18715 work?
CVE-2017-18715 allows an attacker to execute malicious scripts in the victim's browser by tricking them into clicking on a specially crafted link.
How do I fix CVE-2017-18715?
To fix CVE-2017-18715, it is recommended to update the firmware of the affected NETGEAR devices to the latest version provided by the manufacturer.