PT-2020-8354 · NetGear · Wnap320+9
Published
2020-04-21
·
Updated
2020-04-23
·
CVE-2017-18805
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
WAC510 versions prior to 1.3.0.10
WAC120 versions prior to 2.1.4
WNDAP620 versions prior to 2.1.3
WNDAP930 versions prior to 2.1.2
WN604 versions prior to 3.3.7
WNDAP660 versions prior to 3.7.4.0
WNDAP350 versions prior to 3.7.4.0
WNAP320 versions prior to 3.7.4.0
WNAP210v2 versions prior to 3.7.4.0
WNDAP360 versions prior to 3.7.4.0
Description:
Certain NETGEAR devices are affected by command injection.
Recommendations:
For WAC510 versions prior to 1.3.0.10, update to version 1.3.0.10 or later.
For WAC120 versions prior to 2.1.4, update to version 2.1.4 or later.
For WNDAP620 versions prior to 2.1.3, update to version 2.1.3 or later.
For WNDAP930 versions prior to 2.1.2, update to version 2.1.2 or later.
For WN604 versions prior to 3.3.7, update to version 3.3.7 or later.
For WNDAP660 versions prior to 3.7.4.0, update to version 3.7.4.0 or later.
For WNDAP350 versions prior to 3.7.4.0, update to version 3.7.4.0 or later.
For WNAP320 versions prior to 3.7.4.0, update to version 3.7.4.0 or later.
For WNAP210v2 versions prior to 3.7.4.0, update to version 3.7.4.0 or later.
For WNDAP360 versions prior to 3.7.4.0, update to version 3.7.4.0 or later.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wac120
Wac510
Wn604
Wnap210V2
Wnap320
Wndap350
Wndap360
Wndap620
Wndap660
Wndap930