PT-2020-8394 · NetGear · Netgear R7900+4

Published

2020-04-20

·

Updated

2020-04-22

·

CVE-2017-18847

CVSS v3.1

6.2

Medium

VectorAC:L/AV:L/A:N/C:H/I:N/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: NETGEAR R6400v2 versions 1.0.2.31 and earlier NETGEAR R7000P/R6900P versions 1.0.0.55 and earlier NETGEAR R7900 versions 1.0.1.17 and earlier NETGEAR R8300 versions 1.0.2.100 1.0.81 and earlier NETGEAR R8500 versions 1.0.2.100 1.0.81 and earlier NETGEAR D8500 versions 1.0.3.28 and earlier
Description: The issue allows an attacker to read arbitrary files on certain NETGEAR devices.
Recommendations: For NETGEAR R6400v2 version 1.0.2.31 and earlier, update to version 1.0.2.32 or later. For NETGEAR R7000P/R6900P version 1.0.0.55 and earlier, update to version 1.0.0.56 or later. For NETGEAR R7900 version 1.0.1.17 and earlier, update to version 1.0.1.18 or later. For NETGEAR R8300 version 1.0.2.100 1.0.81 and earlier, update to version 1.0.2.100 1.0.82 or later. For NETGEAR R8500 version 1.0.2.100 1.0.81 and earlier, update to version 1.0.2.100 1.0.82 or later. For NETGEAR D8500 version 1.0.3.28 and earlier, update to version 1.0.3.29 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18847

Affected Products

Netgear R8500
Netgear R6400V2
Netgear R7000P/R6900P
Netgear R7900
Netgear R8300