CVE-2017-18853: Infoleak
Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and earlier, R6400v2 1.0.2.18 and earlier, R6700 1.0.1.22 and earlier, R6900 1.0.1.20 and earlier, R7000 1.0.7.10 and earlier, R7000P 1.0.0.58 and earlier, R7100LG 1.0.0.28 and earlier, R7300DST 1.0.0.52 and earlier, R7900 1.0.1.12 and earlier, R8000 1.0.3.46 and earlier, R8300 1.0.2.86 and earlier, R8500 1.0.2.86 and earlier, WNDR3400v3 1.0.1.8 and earlier, and WNDR4500v2 1.0.0.62 and earlier.
Affected Software
Event History
Frequently Asked Questions
Which NETGEAR devices are affected by CVE-2017-18853?
D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and earlier, R6400v2 1.0.2.18 and earlier, R6700 1.0.1.22 and earlier, R6900 1.0.1.20 and earlier, R7000 1.0.7.10 and earlier.
What is the severity of CVE-2017-18853?
The severity is critical with a CVSS score of 6.5.
How can I fix CVE-2017-18853?
Update your NETGEAR device firmware to the latest version provided by the manufacturer.
Where can I find more information about CVE-2017-18853?
You can find more information about CVE-2017-18853 on the NETGEAR security advisory page.
What is the CWE category of CVE-2017-18853?
The CWE category is CWE-200: Information Exposure.