CVE-2017-18735: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, and R6900v2 before 1.2.0.4.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18735?
CVE-2017-18735 is a vulnerability that affects certain NETGEAR devices, allowing an unauthenticated attacker to perform command injection.
Which NETGEAR devices are affected by CVE-2017-18735?
CVE-2017-18735 affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, and R6900v2 before 1.2.0.4.
How severe is CVE-2017-18735?
CVE-2017-18735 has a severity score of 8.8 (high).
How does CVE-2017-18735 work?
CVE-2017-18735 allows an unauthenticated attacker to inject and execute arbitrary commands on vulnerable NETGEAR devices.
How can I fix CVE-2017-18735?
To fix CVE-2017-18735, it is recommended to update the firmware of the affected NETGEAR devices to the latest version provided by the manufacturer.