CVE-2017-18762: Command Injection
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6100 before 1.0.0.57, R6100 before 1.0.1.16, R6900P before 1.2.0.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R7100LG before 1.0.0.40, WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.58.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18762?
The severity of CVE-2017-18762 is high, with a severity score of 8.8.
Which NETGEAR devices are affected by CVE-2017-18762?
The NETGEAR devices affected by CVE-2017-18762 are D3600, D6000, D6100, R6100, R6900P, R7000, R7000P, and R7100LG.
What is the affected firmware version for D3600?
The affected firmware version for D3600 is before 1.0.0.68.
How can an unauthenticated attacker exploit CVE-2017-18762?
An unauthenticated attacker can exploit CVE-2017-18762 through command injection.
Where can I find more information about CVE-2017-18762?
You can find more information about CVE-2017-18762 at the following link: https://kb.netgear.com/000051483/Security-Advisory-for-Pre-Authentication-Command-Injection-on-Some-Routers-and-Gateways-PSV-2017-2451