PT-2020-8331 · NetGear · Jnr1010V2+17

Published

2020-04-22

·

Updated

2020-04-24

·

CVE-2017-18782

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: D6200 versions 1.1.00.23 and earlier D7000 versions 1.0.1.51 and earlier JR6150 versions 1.0.1.11 and earlier JNR1010v2 versions 1.1.0.43 and earlier JWNR2010v5 versions 1.1.0.43 and earlier PR2000 versions 1.0.0.19 and earlier R6020 versions 1.0.0.25 and earlier R6050 versions 1.0.1.11 and earlier R6080 versions 1.0.0.25 and earlier R6120 versions 1.0.0.35 and earlier R6220 versions 1.1.0.59 and earlier R6700v2 versions 1.2.0.11 and earlier R6800 versions 1.2.0.11 and earlier R6900v2 versions 1.2.0.11 and earlier WNDR3700v5 versions 1.1.0.49 and earlier WNR1000v4 versions 1.1.0.43 and earlier WNR2020 versions 1.1.0.43 and earlier WNR2050 versions 1.1.0.43 and earlier
Description: Certain NETGEAR devices are affected by a CSRF issue. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: Update D6200 to version 1.1.00.24 or later. Update D7000 to version 1.0.1.52 or later. Update JR6150 to version 1.0.1.12 or later. Update JNR1010v2 to version 1.1.0.44 or later. Update JWNR2010v5 to version 1.1.0.44 or later. Update PR2000 to version 1.0.0.20 or later. Update R6020 to version 1.0.0.26 or later. Update R6050 to version 1.0.1.12 or later. Update R6080 to version 1.0.0.26 or later. Update R6120 to version 1.0.0.36 or later. Update R6220 to version 1.1.0.60 or later. Update R6700v2 to version 1.2.0.12 or later. Update R6800 to version 1.2.0.12 or later. Update R6900v2 to version 1.2.0.12 or later. Update WNDR3700v5 to version 1.1.0.50 or later. Update WNR1000v4 to version 1.1.0.44 or later. Update WNR2020 to version 1.1.0.44 or later. Update WNR2050 to version 1.1.0.44 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18782

Affected Products

D6200
D7000
Jnr1010V2
Jr6150
Jwnr2010V5
Pr2000
R6020
R6050
R6080
R6120
R6220
R6700V2
R6800
R6900V2
Wndr3700V5
Wnr1000V4
Wnr2020
Wnr2050