PT-2020-8313 · NetGear · Jnr1010V2+27
Published
2020-04-22
·
Updated
2020-04-24
·
CVE-2017-18764
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
D6100 versions 1.0.0.0 through 1.0.0.54
D7000 versions 1.0.0.0 through 1.0.1.49
D7800 versions 1.0.0.0 through 1.0.1.27
JNR1010v2 versions 1.0.0.0 through 1.1.0.43
JR6150 versions 1.0.0.0 through 1.0.1.9
JWNR2010v5 versions 1.0.0.0 through 1.1.0.43
PR2000 versions 1.0.0.0 through 1.0.0.17
R6050 versions 1.0.0.0 through 1.0.1.9
R6100 versions 1.0.0.0 through 1.0.1.13
R6120 versions 1.0.0.0 through 1.0.0.29
R6220 versions 1.0.0.0 through 1.1.0.49
R6700v2 versions 1.0.0.0 through 1.2.0.3
R6800 versions 1.0.0.0 through 1.2.0.3
R6900v2 versions 1.0.0.0 through 1.2.0.3
R7500 versions 1.0.0.0 through 1.0.0.109
R7500v2 versions 1.0.0.0 through 1.0.3.19
R7800 versions 1.0.0.0 through 1.0.2.35
R9000 versions 1.0.0.0 through 1.0.2.51
WN3000RPv3 versions 1.0.0.0 through 1.0.2.49
WNDR3700v4 versions 1.0.0.0 through 1.0.2.87
WNDR3700v5 versions 1.0.0.0 through 1.1.0.47
WNDR4300v1 versions 1.0.0.0 through 1.0.2.89
WNDR4300v2 versions 1.0.0.0 through 1.0.0.47
WNDR4500v3 versions 1.0.0.0 through 1.0.0.47
WNR1000v4 versions 1.0.0.0 through 1.1.0.43
WNR2000v5 versions 1.0.0.0 through 1.0.0.57
WNR2020 versions 1.0.0.0 through 1.1.0.43
WNR2050 versions 1.0.0.0 through 1.1.0.43
Description:
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
Recommendations:
Update D6100 to version 1.0.0.55 or later.
Update D7000 to version 1.0.1.50 or later.
Update D7800 to version 1.0.1.28 or later.
Update JNR1010v2 to version 1.1.0.44 or later.
Update JR6150 to version 1.0.1.10 or later.
Update JWNR2010v5 to version 1.1.0.44 or later.
Update PR2000 to version 1.0.0.18 or later.
Update R6050 to version 1.0.1.10 or later.
Update R6100 to version 1.0.1.14 or later.
Update R6120 to version 1.0.0.30 or later.
Update R6220 to version 1.1.0.50 or later.
Update R6700v2 to version 1.2.0.4 or later.
Update R6800 to version 1.2.0.4 or later.
Update R6900v2 to version 1.2.0.4 or later.
Update R7500 to version 1.0.0.110 or later.
Update R7500v2 to version 1.0.3.20 or later.
Update R7800 to version 1.0.2.36 or later.
Update R9000 to version 1.0.2.52 or later.
Update WN3000RPv3 to version 1.0.2.50 or later.
Update WNDR3700v4 to version 1.0.2.88 or later.
Update WNDR3700v5 to version 1.1.0.48 or later.
Update WNDR4300v1 to version 1.0.2.90 or later.
Update WNDR4300v2 to version 1.0.0.48 or later.
Update WNDR4500v3 to version 1.0.0.48 or later.
Update WNR1000v4 to version 1.1.0.44 or later.
Update WNR2000v5 to version 1.0.0.58 or later.
Update WNR2020 to version 1.1.0.44 or later.
Update WNR2050 to version 1.1.0.44 or later.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D6100
D7000
D7800
Jnr1010V2
Jr6150
Jwnr2010V5
Pr2000
R6050
R6100
R6120
R6220
R6700V2
R6800
R6900V2
R7500
R7500V2
R7800
R9000
Wn3000Rpv3
Wndr3700V4
Wndr3700V5
Wndr4300V1
Wndr4300V2
Wndr4500V3
Wnr1000V4
Wnr2000V5
Wnr2020
Wnr2050