PT-2020-8296 · NetGear · Netgear Ex3800+7

Popeax

·

Published

2020-04-23

·

Updated

2020-04-23

·

CVE-2017-18747

CVSS v3.1

8.8

High

VectorAC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: NETGEAR EX3700 versions prior to 1.0.0.64 NETGEAR EX3800 versions prior to 1.0.0.64 NETGEAR EX6000 versions prior to 1.0.0.24 NETGEAR EX6130 versions prior to 1.0.0.16 NETGEAR EX6400 versions prior to 1.0.1.60 NETGEAR EX7000 versions prior to 1.0.0.50 NETGEAR EX7300 versions prior to 1.0.1.60 NETGEAR WN2500RPv2 versions prior to 1.0.1.46
Description: The issue is related to the incorrect configuration of security settings in certain NETGEAR devices.
Recommendations: For NETGEAR EX3700 versions prior to 1.0.0.64, update to version 1.0.0.64 or later. For NETGEAR EX3800 versions prior to 1.0.0.64, update to version 1.0.0.64 or later. For NETGEAR EX6000 versions prior to 1.0.0.24, update to version 1.0.0.24 or later. For NETGEAR EX6130 versions prior to 1.0.0.16, update to version 1.0.0.16 or later. For NETGEAR EX6400 versions prior to 1.0.1.60, update to version 1.0.1.60 or later. For NETGEAR EX7000 versions prior to 1.0.0.50, update to version 1.0.0.50 or later. For NETGEAR EX7300 versions prior to 1.0.1.60, update to version 1.0.1.60 or later. For NETGEAR WN2500RPv2 versions prior to 1.0.1.46, update to version 1.0.1.46 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18747

Affected Products

Netgear Ex3700
Netgear Ex3800
Netgear Ex6000
Netgear Ex6130
Netgear Ex6400
Netgear Ex7000
Netgear Ex7300
Netgear Wn2500Rpv2