CVE-2017-18858: OS Command Injection
Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300-52G 12.0.2.11 and earlier, M4300-28G-POE+ 12.0.2.11 and earlier, M4300-52G-POE+ 12.0.2.11 and earlier, M4300-8X8F 12.0.2.11 and earlier, M4300-12X12F 12.0.2.11 and earlier, M4300-24X24F 12.0.2.11 and earlier, M4300-24X 12.0.2.11 and earlier, and M4300-48X 12.0.2.11 and earlier.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NETGEAR command execution vulnerability?
The vulnerability ID for this NETGEAR command execution vulnerability is CVE-2017-18858.
Which devices are affected by this command execution vulnerability?
This command execution vulnerability affects NETGEAR devices, including M4200-10MG-POE+, M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, and others.
What is the severity of CVE-2017-18858 vulnerability?
The severity of CVE-2017-18858 vulnerability is critical with a CVSS score of 9.8.
How can I fix the NETGEAR command execution vulnerability (CVE-2017-18858)?
To fix the NETGEAR command execution vulnerability (CVE-2017-18858), it is recommended to update the firmware of the affected devices to version 12.0.2.12 (or later) as mentioned in the official security advisory.
Where can I find more information about this NETGEAR command execution vulnerability?
You can find more information about this NETGEAR command execution vulnerability in the official NETGEAR security advisory available at: https://kb.netgear.com/000038655/Security-Advisory-for-Unauthenticated-Remote-Code-Execution-on-M4200-and-M4300-PSV-2017-1971