CVE-2017-18766: Infoleak
Published Apr 22, 2020
·Updated
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects DST6501 before 1.1.0.6 and WNR2000v2 before 1.2.0.8.
Affected Software
4 affected components
Netgear Dst6501 Firmware<1.1.0.6
Netgear DST6501
Netgear Wnr2000 Firmware<1.2.0.8
Netgear WNR2000=v2
Event History
Apr 22, 2020
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2017-18766?
CVE-2017-18766 is a vulnerability that affects certain NETGEAR devices, allowing an attacker to read arbitrary files.
2
Which NETGEAR devices are affected by CVE-2017-18766?
The NETGEAR DST6501 before 1.1.0.6 and WNR2000v2 before 1.2.0.8 are affected by CVE-2017-18766.
3
What is the severity of CVE-2017-18766?
The severity of CVE-2017-18766 is high with a CVSS score of 6.5.
4
How can an attacker exploit CVE-2017-18766?
An attacker can exploit CVE-2017-18766 to gain unauthorized access and read arbitrary files on vulnerable NETGEAR devices.
5
How can I fix CVE-2017-18766?
To fix CVE-2017-18766, it is recommended to update the firmware of the affected NETGEAR devices to versions 1.1.0.6 (DST6501) and 1.2.0.8 (WNR2000v2) or later.