First published: Wed Apr 22 2020(Updated: )
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.90, and WNR2000v5 before 1.0.0.58.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Wndr3700 Firmware | <1.0.2.88 | |
Netgear WNDR3700 | =v4 | |
Netgear Wndr4300 Firmware | <1.0.2.90 | |
Netgear Wndr4300 | =v1 | |
Netgear Wnr2000 Firmware | <1.0.0.58 | |
Netgear WNR2000 | =v5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18754 is a vulnerability that allows an authenticated user to perform command injection on certain NETGEAR devices.
WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.90, and WNR2000v5 before 1.0.0.58 are affected by CVE-2017-18754.
CVE-2017-18754 has a severity rating of 6.8 (medium).
To fix CVE-2017-18754, it is recommended to update the firmware of the affected NETGEAR devices to the latest version.
More information about CVE-2017-18754 can be found in the Netgear security advisory: https://kb.netgear.com/000051494/Security-Advisory-for-Post-Authentication-Command-Injection-on-Routers-PSV-2017-0329.