First published: Wed Apr 22 2020(Updated: )
Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000P before 1.0.0.86, R6900P before 1.0.0.56, R7300 before 1.0.0.54, R8300 before 1.0.2.106, R8500 before 1.0.2.106, DGN2200v4 before 1.0.0.86, DGND2200Bv4 before 1.0.0.86, R6050 before 1.0.0.86, JR6150 before 1.0.1.10, R6220 before 1.1.0.50, and WNDR3700v5 before V1.1.0.48.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6300 Firmware | <1.0.4.8 | |
Netgear R6300 | =v2 | |
Netgear R6400 Firmware | <1.0.2.32 | |
NETGEAR R6400 | =v2 | |
Netgear R6700 Firmware | <1.0.1.22 | |
NETGEAR R6700 | ||
Netgear R6900 Firmware | <1.0.1.22 | |
Netgear R6900 | ||
Netgear R7000p Firmware | <1.0.0.86 | |
Netgear R7000P | ||
Netgear R6900p Firmware | <1.0.0.56 | |
Netgear R6900P | ||
Netgear R7300 Firmware | <1.0.0.54 | |
Netgear R7300 | ||
Netgear R8300 Firmware | <1.0.2.106 | |
NETGEAR R8300 | ||
Netgear R8500 Firmware | <1.0.2.106 | |
NETGEAR R8500 | ||
Netgear Dgn2200 Firmware | <1.0.0.86 | |
Netgear DGN2200 | =v4 | |
Netgear Dgnd2200b Firmware | <1.0.0.86 | |
Netgear Dgnd2200b | =v4 | |
Netgear R6050 Firmware | <1.0.0.86 | |
Netgear R6050 | ||
Netgear Jr6150 Firmware | <1.0.1.10 | |
Netgear Jr6150 | ||
Netgear R6220 Firmware | <1.1.0.50 | |
NETGEAR R6220 | ||
Netgear Wndr3700 Firmware | <1.1.0.48 | |
Netgear WNDR3700 | =v5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CSRF vulnerability CVE-2017-18755 affects certain NETGEAR devices including R6300v2, R6400v2, R6700, R6900, R7000P, R6900P, R7300, R8300, R8500, DGN2200v4, and more.
The CSRF vulnerability CVE-2017-18755 has a severity rating of 8.8 (high).
To fix the CSRF vulnerability CVE-2017-18755, update the firmware of the affected NETGEAR devices to the latest version provided by the manufacturer.
You can find more information about the CSRF vulnerability CVE-2017-18755 in the Netgear Security Advisory PSV-2017-0333.
The CSRF vulnerability CVE-2017-18755 is associated with CWE-352.