CVE-2017-18794 Information

Description

Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77 R6400 before 1.0.1.24 R6700 before 1.0.1.26 R7000 before 1.0.9.10 R7100LG before 1.0.0.32 R7900 before 1.0.1.18 R8000 before 1.0.3.54 R8500 before 1.0.2.100 and D6100 before 1.0.0.50_0.0.50.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://kb.netgear.com/000049368/Security-Advisory-for-Command-Injection-Vulnerability-on-D6100-and-Some-Routers-PSV-2017-0321

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.4

Share on: