PT-2020-8252 · NetGear · Ex6150V2+28

Published

2020-04-24

·

Updated

2020-05-11

·

CVE-2017-18703

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: D1500 versions 1.0.0.0 through 1.0.0.24 D500 versions 1.0.0.0 through 1.0.0.24 D6100 versions 1.0.0.0 through 1.0.0.54 D7000 versions 1.0.0.0 through 1.0.1.49 D7800 versions 1.0.0.0 through 1.0.1.27 EX6100v2 versions 1.0.0.0 through 1.0.1.59 EX6150v2 versions 1.0.0.0 through 1.0.1.59 JNR1010v2 versions 1.0.0.0 through 1.1.0.45 JR6150 versions 1.0.0.0 through 1.0.1.15 JWNR2010v5 versions 1.0.0.0 through 1.1.0.45 PR2000 versions 1.0.0.0 through 1.0.0.17 R6020 versions 1.0.0.0 through 1.0.0.25 R6050 versions 1.0.0.0 through 1.0.1.15 R6080 versions 1.0.0.0 through 1.0.0.25 R6100 versions 1.0.0.0 through 1.0.1.19 R6220 versions 1.0.0.0 through 1.1.0.59 R7500 versions 1.0.0.0 through 1.0.0.117 R7500v2 versions 1.0.0.0 through 1.0.3.19 R7800 versions 1.0.0.0 through 1.0.2.39 R9000 versions 1.0.0.0 through 1.0.2.51 WN3000RPv3 versions 1.0.0.0 through 1.0.2.49 WN3100RPv2 versions 1.0.0.0 through 1.0.0.39 WNDR3700v5 versions 1.0.0.0 through 1.1.0.47 WNDR4300v2 versions 1.0.0.0 through 1.0.0.47 WNDR4500v3 versions 1.0.0.0 through 1.0.0.47 WNR1000v4 versions 1.0.0.0 through 1.1.0.45 WNR2000v5 versions 1.0.0.0 through 1.0.0.61 WNR2020 versions 1.0.0.0 through 1.1.0.45 WNR2050 versions 1.0.0.0 through 1.1.0.45
Description: Certain NETGEAR devices are affected by a CSRF issue.
Recommendations: Update D1500 to version 1.0.0.25 or later. Update D500 to version 1.0.0.25 or later. Update D6100 to version 1.0.0.55 or later. Update D7000 to version 1.0.1.50 or later. Update D7800 to version 1.0.1.28 or later. Update EX6100v2 to version 1.0.1.60 or later. Update EX6150v2 to version 1.0.1.60 or later. Update JNR1010v2 to version 1.1.0.46 or later. Update JR6150 to version 1.0.1.16 or later. Update JWNR2010v5 to version 1.1.0.46 or later. Update PR2000 to version 1.0.0.18 or later. Update R6020 to version 1.0.0.26 or later. Update R6050 to version 1.0.1.16 or later. Update R6080 to version 1.0.0.26 or later. Update R6100 to version 1.0.1.20 or later. Update R6220 to version 1.1.0.60 or later. Update R7500 to version 1.0.0.118 or later. Update R7500v2 to version 1.0.3.20 or later. Update R7800 to version 1.0.2.40 or later. Update R9000 to version 1.0.2.52 or later. Update WN3000RPv3 to version 1.0.2.50 or later. Update WN3100RPv2 to version 1.0.0.40 or later. Update WNDR3700v5 to version 1.1.0.48 or later. Update WNDR4300v2 to version 1.0.0.48 or later. Update WNDR4500v3 to version 1.0.0.48 or later. Update WNR1000v4 to version 1.1.0.46 or later. Update WNR2000v5 to version 1.0.0.62 or later. Update WNR2020 to version 1.1.0.46 or later. Update WNR2050 to version 1.1.0.46 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18703

Affected Products

D1500
D500
D6100
D7000
D7800
Ex6100V2
Ex6150V2
Jnr1010V2
Jr6150
Jwnr2010V5
Pr2000
R6020
R6050
R6080
R6100
R6220
R7500
R7500V2
R7800
R9000
Wn3000Rpv3
Wn3100Rpv2
Wndr3700V5
Wndr4300V2
Wndr4500V3
Wnr1000V4
Wnr2000V5
Wnr2020
Wnr2050