PT-2020-8410 · NetGear · Wnap320+8
Published
2020-04-28
·
Updated
2020-05-05
·
CVE-2017-18863
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
NETGEAR WN604 versions 3.3.3 and earlier
NETGEAR WNAP210v2 versions 3.5.20.0 and earlier
NETGEAR WNAP320 versions 3.5.20.0 and earlier
NETGEAR WNDAP350 versions 3.5.20.0 and earlier
NETGEAR WNDAP360 versions 3.5.20.0 and earlier
NETGEAR WNDAP620 versions 2.0.11 and earlier
NETGEAR WNDAP660 versions 3.5.20.0 and earlier
NETGEAR WND930 versions 2.0.11 and earlier
NETGEAR WAC120 versions 2.0.7 and earlier
Description:
The issue allows for command execution via a PHP form.
Recommendations:
For NETGEAR WN604 versions 3.3.3 and earlier, update to a version later than 3.3.3.
For NETGEAR WNAP210v2 versions 3.5.20.0 and earlier, update to a version later than 3.5.20.0.
For NETGEAR WNAP320 versions 3.5.20.0 and earlier, update to a version later than 3.5.20.0.
For NETGEAR WNDAP350 versions 3.5.20.0 and earlier, update to a version later than 3.5.20.0.
For NETGEAR WNDAP360 versions 3.5.20.0 and earlier, update to a version later than 3.5.20.0.
For NETGEAR WNDAP620 versions 2.0.11 and earlier, update to a version later than 2.0.11.
For NETGEAR WNDAP660 versions 3.5.20.0 and earlier, update to a version later than 3.5.20.0.
For NETGEAR WND930 versions 2.0.11 and earlier, update to a version later than 2.0.11.
For NETGEAR WAC120 versions 2.0.7 and earlier, update to a version later than 2.0.7.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wac120
Wn604
Wnap210V2
Wnap320
Wnd930
Wndap350
Wndap360
Wndap620
Wndap660