PT-2020-8351 · NetGear · Netgear R7800+4
Published
2020-04-21
·
Updated
2020-04-23
·
CVE-2017-18802
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
NETGEAR R6100 versions prior to 1.0.1.14
NETGEAR R7500 versions prior to 1.0.0.110
NETGEAR R7500v2 versions prior to 1.0.3.16
NETGEAR R7800 versions prior to 1.0.2.32
NETGEAR EX6200v2 versions prior to 1.0.1.50
NETGEAR D7800 versions prior to 1.0.1.22
Description:
The issue is related to command injection, affecting certain NETGEAR devices.
Recommendations:
For R6100 version prior to 1.0.1.14, update to version 1.0.1.14 or later.
For R7500 version prior to 1.0.0.110, update to version 1.0.0.110 or later.
For R7500v2 version prior to 1.0.3.16, update to version 1.0.3.16 or later.
For R7800 version prior to 1.0.2.32, update to version 1.0.2.32 or later.
For EX6200v2 version prior to 1.0.1.50, update to version 1.0.1.50 or later.
For D7800 version prior to 1.0.1.22, update to version 1.0.1.22 or later.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear R7800
Netgear Ex6200V2
Netgear R6100
Netgear R7500
Netgear R7500V2