First published: Mon Apr 20 2020(Updated: )
Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.0.36, AC1450 before 1.0.0.36, R7300 before 1.0.0.54, and R8500 before 1.0.2.94.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear R6300 Firmware | <1.0.0.36 | |
Netgear R6300 | =v2 | |
Netgear Ac1450 Firmware | <1.0.0.36 | |
Netgear Ac1450 | ||
Netgear R7300 Firmware | <1.0.0.54 | |
Netgear R7300 | ||
Netgear R8500 Firmware | <1.0.2.94 | |
NETGEAR R8500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18848 is a vulnerability that affects certain NETGEAR devices and allows for Cross-Site Request Forgery (CSRF) attacks.
CVE-2017-18848 affects R6300v2 before 1.0.0.36, AC1450 before 1.0.0.36, R7300 before 1.0.0.54, and R8500 before 1.0.2.94.
CVE-2017-18848 has a severity value of 8.8 (high).
To fix CVE-2017-18848, it is recommended to update the firmware of the affected NETGEAR devices to the latest version.
You can find more information about CVE-2017-18848 on the NETGEAR knowledge base at the following link: [https://kb.netgear.com/000049011/Security-Advisory-for-Cross-Site-Request-Forgery-on-Some-Routers-PSV-2017-0334](https://kb.netgear.com/000049011/Security-Advisory-for-Cross-Site-Request-Forgery-on-Some-Routers-PSV-2017-0334)