First published: Tue Apr 21 2020(Updated: )
Certain NETGEAR devices are affected by reflected XSS. This affects R6700v2 before 1.1.0.42 and R6800 before 1.1.0.42.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R6700 firmware | <1.1.0.42 | |
NETGEAR R6700v1 firmware | =v2 | |
NETGEAR R6800 firmware | <1.1.0.42 | |
NETGEAR R6800 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18800 has a moderate severity due to the potential for reflected cross-site scripting attacks.
To fix CVE-2017-18800, update your NETGEAR R6700v2 to version 1.1.0.42 or later and the R6800 to version 1.1.0.42 or later.
CVE-2017-18800 affects NETGEAR R6700v2 devices before version 1.1.0.42 and R6800 devices before version 1.1.0.42.
Reflected XSS in CVE-2017-18800 allows attackers to inject malicious scripts that can execute in the user's browser.
You can still use your device, but it is highly recommended to update it to avoid vulnerability to attacks.