PT-2020-8394 · NetGear · Netgear R7900+4
Published
2020-04-20
·
Updated
2020-04-22
·
CVE-2017-18847
CVSS v3.1
6.2
Medium
| Vector | AC:L/AV:L/A:N/C:H/I:N/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions:
NETGEAR R6400v2 versions 1.0.2.31 and earlier
NETGEAR R7000P/R6900P versions 1.0.0.55 and earlier
NETGEAR R7900 versions 1.0.1.17 and earlier
NETGEAR R8300 versions 1.0.2.100 1.0.81 and earlier
NETGEAR R8500 versions 1.0.2.100 1.0.81 and earlier
NETGEAR D8500 versions 1.0.3.28 and earlier
Description:
The issue allows an attacker to read arbitrary files on certain NETGEAR devices.
Recommendations:
For NETGEAR R6400v2 version 1.0.2.31 and earlier, update to version 1.0.2.32 or later.
For NETGEAR R7000P/R6900P version 1.0.0.55 and earlier, update to version 1.0.0.56 or later.
For NETGEAR R7900 version 1.0.1.17 and earlier, update to version 1.0.1.18 or later.
For NETGEAR R8300 version 1.0.2.100 1.0.81 and earlier, update to version 1.0.2.100 1.0.82 or later.
For NETGEAR R8500 version 1.0.2.100 1.0.81 and earlier, update to version 1.0.2.100 1.0.82 or later.
For NETGEAR D8500 version 1.0.3.28 and earlier, update to version 1.0.3.29 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear R8500
Netgear R6400V2
Netgear R7000P/R6900P
Netgear R7900
Netgear R8300