CVE-2017-18832: XSS
Certain NETGEAR devices are affected by stored XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.
Affected Software
Event History
Frequently Asked Questions
Which devices are affected by the stored XSS vulnerability (CVE-2017-18832)?
Certain NETGEAR devices including M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, M4300-24X24F, M4300-24X, M4300-48X, and M4200 are affected.
What is the severity of CVE-2017-18832?
The severity of CVE-2017-18832 is medium with a CVSS score of 4.8.
How does the stored XSS vulnerability (CVE-2017-18832) affect NETGEAR devices?
The stored XSS vulnerability allows an attacker to inject malicious scripts into the device's web interface, potentially leading to unauthorized access or data theft.
How can I fix the stored XSS vulnerability (CVE-2017-18832) on my affected NETGEAR device?
To fix the vulnerability, you should update the firmware of your device to version 12.0.2.15 or later, which contains a patch for the XSS vulnerability.
Where can I find more information about the stored XSS vulnerability (CVE-2017-18832)?
You can find more information about the vulnerability and the necessary firmware updates on the NETGEAR website.