CVE-2017-18786: Command Injection
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18786?
CVE-2017-18786 is a vulnerability that affects certain NETGEAR devices, allowing an attacker to execute arbitrary commands on the affected devices.
Which NETGEAR devices are affected by CVE-2017-18786?
The following NETGEAR devices are affected by CVE-2017-18786: D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
How severe is CVE-2017-18786?
CVE-2017-18786 has a severity score of 7.8, which is classified as high severity.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2017-18786?
CVE-2017-18786 is associated with CWE-77 and CWE-74.
How can I fix CVE-2017-18786?
To fix CVE-2017-18786, you should update the firmware of the affected NETGEAR devices to version 1.1.00.24 for D6200, 1.1.0.44 for JNR1010v2, 1.0.1.12 for JR6150, 1.1.0.44 for JWNR2010v5, 1.0.0.20 for PR2000, 1.0.1.12 for R6050, 1.1.0.44 for WNR1000v4, 1.1.0.44 for WNR2020, and 1.1.0.44 for WNR2050.