First published: Tue Apr 21 2020(Updated: )
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects R6400 before 1.0.1.24, R7900 before 1.0.1.18, R8000 before 1.0.3.54, and R8500 before 1.0.2.100.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R6400 firmware | <1.0.1.24 | |
NETGEAR R6400 firmware | ||
NETGEAR R7900P firmware | <1.0.1.18 | |
NETGEAR R7900P firmware | ||
NETGEAR R8000 firmware | <1.0.3.54 | |
NETGEAR R8000 firmware | ||
NETGEAR R8500 | <1.0.2.100 | |
NETGEAR R8500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18797 is classified as a high severity vulnerability due to the potential for arbitrary file reading.
To fix CVE-2017-18797, users should upgrade affected NETGEAR devices to the latest firmware versions: R6400 to at least 1.0.1.24, R7900 to at least 1.0.1.18, R8000 to at least 1.0.3.54, and R8500 to at least 1.0.2.100.
CVE-2017-18797 affects the NETGEAR R6400, R7900, R8000, and R8500 models when running specific older firmware versions.
While you can continue to use your NETGEAR device, it is not recommended due to the security risks associated with the vulnerability.
CVE-2017-18797 can be exploited by an attacker who can remotely read arbitrary files, potentially exposing sensitive information.