First published: Mon Apr 20 2020(Updated: )
Certain NETGEAR devices are affected by CSRF. This affects R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200DW-1FRNAS before 1.0.0.32.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NETGEAR R7300 firmware | <1.0.0.54 | |
NETGEAR R7300 firmware | ||
NETGEAR R8500 | <1.0.2.94 | |
NETGEAR R8500 | ||
NETGEAR DGN2200B firmware | <1.0.0.55 | |
NETGEAR DGN2200M | =v1 | |
NETGEAR D2200D firmware | <1.0.0.32 | |
NETGEAR D2200D | ||
NETGEAR D2200DW firmware | <1.0.0.32 | |
NETGEAR D2200DW |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18842 is a vulnerability that affects certain NETGEAR devices and allows for Cross-Site Request Forgery (CSRF) attacks.
CVE-2017-18842 affects NETGEAR devices including R7300 before 1.0.0.54, R8500 before 1.0.2.94, DGN2200v1 before 1.0.0.55, and D2200D/D2200DW-1FRNAS before 1.0.0.32.
CVE-2017-18842 is considered a high severity vulnerability with a severity score of 8.8 out of 10.
Cross-Site Request Forgery (CSRF) is an attack that tricks the victim into executing unwanted actions on a targeted website without their knowledge or consent.
To fix CVE-2017-18842, it is recommended to update the firmware of the affected NETGEAR devices to the latest version provided by the vendor.