PT-2020-8336 · NetGear · Wnr2020+8

Published

2020-04-22

·

Updated

2020-04-27

·

CVE-2017-18787

CVSS v3.1

8.4

High

VectorAC:L/AV:L/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: D6200 versions prior to 1.1.00.24 JNR1010v2 versions prior to 1.1.0.44 JR6150 versions prior to 1.0.1.12 JWNR2010v5 versions prior to 1.1.0.44 PR2000 versions prior to 1.0.0.20 R6050 versions prior to 1.0.1.12 WNR1000v4 versions prior to 1.1.0.44 WNR2020 versions prior to 1.1.0.44 WNR2050 versions prior to 1.1.0.44
Description: Certain NETGEAR devices are affected by command injection.
Recommendations: For D6200 version prior to 1.1.00.24, update to version 1.1.00.24 or later. For JNR1010v2 version prior to 1.1.0.44, update to version 1.1.0.44 or later. For JR6150 version prior to 1.0.1.12, update to version 1.0.1.12 or later. For JWNR2010v5 version prior to 1.1.0.44, update to version 1.1.0.44 or later. For PR2000 version prior to 1.0.0.20, update to version 1.0.0.20 or later. For R6050 version prior to 1.0.1.12, update to version 1.0.1.12 or later. For WNR1000v4 version prior to 1.1.0.44, update to version 1.1.0.44 or later. For WNR2020 version prior to 1.1.0.44, update to version 1.1.0.44 or later. For WNR2050 version prior to 1.1.0.44, update to version 1.1.0.44 or later.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18787

Affected Products

D6200
Jnr1010V2
Jr6150
Jwnr2010V5
Pr2000
R6050
Wnr1000V4
Wnr2020
Wnr2050