PT-2020-8325 · NetGear · Jnr1010V2+15
Joel St. John
·
Published
2020-04-22
·
Updated
2020-04-24
·
CVE-2017-18776
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
D6100 versions prior to V1.0.0.55
D7000 versions prior to V1.0.1.50
D7800 versions prior to V1.0.1.24
JNR1010v2 versions prior to 1.1.0.40
JWNR2010v5 versions prior to 1.1.0.40
R6100 versions prior to 1.0.1.12
R6220 versions prior to 1.1.0.50
R7500 versions prior to 1.0.0.108
R7500v2 versions prior to 1.0.3.10
WNDR4300v1 versions prior to 1.0.2.88
WNDR4300v2 versions prior to 1.0.0.48
WNDR4500v3 versions prior to 1.0.0.48
WNR1000v4 versions prior to 1.1.0.40
WNR2000v5 versions prior to 1.0.0.42
WNR2020 versions prior to 1.1.0.40
WNR2050 versions prior to 1.1.0.40
Description:
Certain NETGEAR devices are affected by authentication bypass.
Recommendations:
As a temporary workaround, consider disabling authentication for the affected devices until a patch is available.
For D6100, update to V1.0.0.55 or later.
For D7000, update to V1.0.1.50 or later.
For D7800, update to V1.0.1.24 or later.
For JNR1010v2, update to 1.1.0.40 or later.
For JWNR2010v5, update to 1.1.0.40 or later.
For R6100, update to 1.0.1.12 or later.
For R6220, update to 1.1.0.50 or later.
For R7500, update to 1.0.0.108 or later.
For R7500v2, update to 1.0.3.10 or later.
For WNDR4300v1, update to 1.0.2.88 or later.
For WNDR4300v2, update to 1.0.0.48 or later.
For WNDR4500v3, update to 1.0.0.48 or later.
For WNR1000v4, update to 1.1.0.40 or later.
For WNR2000v5, update to 1.0.0.42 or later.
For WNR2020, update to 1.1.0.40 or later.
For WNR2050, update to 1.1.0.40 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D6100
D7000
D7800
Jnr1010V2
Jwnr2010V5
R6100
R6220
R7500
R7500V2
Wndr4300V1
Wndr4300V2
Wndr4500V3
Wnr1000V4
Wnr2000V5
Wnr2020
Wnr2050