PT-2020-8399 · NetGear · Netgear R7300Dst+3

Published

2020-04-20

·

Updated

2020-04-22

·

CVE-2017-18852

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NETGEAR R7300DST versions prior to 1.0.0.54 NETGEAR R8300 versions prior to 1.0.2.100 1.0.82 NETGEAR R8500 versions prior to 1.0.2.100 1.0.82 NETGEAR WNDR3400v3 versions prior to 1.0.1.14
Description: Certain NETGEAR devices are affected by CSRF and authentication bypass.
Recommendations: For R7300DST version prior to 1.0.0.54, update to version 1.0.0.54 or later. For R8300 version prior to 1.0.2.100 1.0.82, update to version 1.0.2.100 1.0.82 or later. For R8500 version prior to 1.0.2.100 1.0.82, update to version 1.0.2.100 1.0.82 or later. For WNDR3400v3 version prior to 1.0.1.14, update to version 1.0.1.14 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18852

Affected Products

Netgear R7300Dst
Netgear R8300
Netgear R8500
Netgear Wndr3400V3