First published: Mon Apr 20 2020(Updated: )
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6700 Firmware | <1.1.0.38 | |
NETGEAR R6700v1 firmware | =v2 | |
NETGEAR R6800 firmware | <1.1.0.38 | |
NETGEAR R6800 firmware | ||
NETGEAR D7000v1 firmware | <1.0.1.50 | |
NETGEAR D7000 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18844 is considered a serious vulnerability due to the disclosure of administrative credentials on affected NETGEAR devices.
To fix CVE-2017-18844, upgrade your NETGEAR device to the latest firmware version: R6700v2 to 1.1.0.38, R6800 to 1.1.0.38, or D7000 to 1.0.1.50.
CVE-2017-18844 affects NETGEAR R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.
If CVE-2017-18844 is not addressed, unauthorized users may exploit the vulnerability to gain administrative access to the affected devices.
Yes, CVE-2017-18844 allows for the unauthorized disclosure of administrative credentials, which can lead to further exploits.