First published: Tue Apr 21 2020(Updated: )
Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050 before 1.1.0.40, WNR614 before 1.1.0.40, WNR618 before 1.1.0.40, and D7000 before 1.0.1.50.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6050 Firmware | <1.0.1.7 | |
Netgear R6050 | ||
Netgear Jr6150 Firmware | <1.0.1.7 | |
Netgear Jr6150 | ||
Netgear Pr2000 Firmware | <1.0.0.17 | |
Netgear Pr2000 | ||
Netgear R6220 Firmware | <1.1.0.50 | |
NETGEAR R6220 | ||
Netgear Wndr3700 Firmware | <1.1.0.48 | |
Netgear WNDR3700 | =v5 | |
Netgear Jnr1010 Firmware | <1.1.0.40 | |
NETGEAR JNR1010 | =v2 | |
Netgear Jwnr2010 Firmware | <1.1.0.40 | |
Netgear Jwnr2010 | =v5 | |
Netgear Wnr1000 Firmware | <1.1.0.40 | |
Netgear WNR1000 | =v4 | |
Netgear Wnr2020 Firmware | <1.1.0.40 | |
Netgear Wnr2020 | ||
Netgear Wnr2050 Firmware | <1.1.0.40 | |
Netgear Wnr2050 | ||
Netgear Wnr614 Firmware | <1.1.0.40 | |
Netgear WNR614 | ||
Netgear Wnr618 Firmware | <1.1.0.40 | |
Netgear Wnr618 | ||
Netgear D7000 Firmware | <1.0.1.50 | |
NETGEAR D7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CSRF stands for Cross-Site Request Forgery, it is a type of attack that tricks the victim into making a malicious request.
The NETGEAR devices affected by CSRF include R6050/JR6150, PR2000, R6220, WNDR3700v5, JNR1010v2, JWNR2010v5, WNR1000v4, WNR2020, WNR2050, WNR614, WNR618, and D7000.
CVE-2017-18791 has a severity rating of 8.8 (High).
To fix CVE-2017-18791, upgrade your NETGEAR device firmware to the specified versions which include the necessary security patches.
More information about CVE-2017-18791 can be found in the NETGEAR security advisory: [link](https://kb.netgear.com/000049371/Security-Advisory-for-Cross-Site-Request-Forgery-Vulnerability-on-D7000-and-Some-Routers-PSV-2017-0386).