CVE-2017-6862: NETGEAR Multiple Devices Buffer Overflow Vulnerability
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
Other sources
Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6862?
CVE-2017-6862 has a high severity rating due to the potential for remote code execution and authentication bypass.
How do I fix CVE-2017-6862?
To fix CVE-2017-6862, update the firmware of your NETGEAR WNR2000v3, WNR2000v4, or WNR2000v5 devices to the latest version.
Which NETGEAR devices are affected by CVE-2017-6862?
CVE-2017-6862 affects NETGEAR WNR2000v3 firmware versions before 1.1.2.14, WNR2000v4 before 1.0.0.66, and WNR2000v5 before 1.0.0.42.
What happens if I do not address CVE-2017-6862?
If CVE-2017-6862 is not addressed, attackers could exploit the vulnerability to gain unauthorized access and execute malicious code remotely.
Is there a workaround for CVE-2017-6862?
There is no official workaround for CVE-2017-6862; the recommended solution is to promptly update to the latest firmware.