First published: Mon Apr 20 2020(Updated: )
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.46, and D7000 before 1.0.1.50.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6220 Firmware | <1.1.0.46 | |
NETGEAR R6220 | ||
Netgear R6700 Firmware | <1.1.0.38 | |
NETGEAR R6700 | =v2 | |
Netgear R6800 Firmware | <1.1.0.38 | |
Netgear R6800 | ||
Netgear Wndr3700 Firmware | <1.1.0.46 | |
Netgear WNDR3700 | =v5 | |
Netgear D7000 Firmware | <1.0.1.50 | |
NETGEAR D7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Certain NETGEAR devices are affected by command injection, including R6220, R6700v2, R6800, WNDR3700v5, and D7000.
The severity of CVE-2017-18841 is medium, with a severity value of 6.7.
To fix CVE-2017-18841, update the firmware of affected NETGEAR devices to versions 1.1.0.46 for R6220, 1.1.0.38 for R6700v2 and R6800, 1.1.0.46 for WNDR3700v5, and 1.0.1.50 for D7000.
Command injection is a vulnerability that allows an attacker to execute arbitrary commands on a target system.
You can find more information about CVE-2017-18841 on the NETGEAR Knowledge Base at https://kb.netgear.com/000049018/Security-Advisory-for-Command-Injection-on-Some-Routers-and-a-Modem-Router-PSV-2017-2158.