PT-2020-8519 · NetGear · Netgear Wc7600V1+4
Alexander Oleinik
+5
·
Published
2020-04-01
·
Updated
2020-08-24
·
CVE-2018-11106
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
NETGEAR WC7500 versions prior to 6.5.3.5
NETGEAR WC7520 versions prior to 2.5.0.46
NETGEAR WC7600v1 versions prior to 6.5.3.5
NETGEAR WC7600v2 versions prior to 6.5.3.5
NETGEAR WC9500 versions prior to 6.5.3.5
Description:
The issue is a pre-authentication command injection in the request handler.php file. This allows for potential exploitation without the need for authentication. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations:
For NETGEAR WC7500, update to firmware version 6.5.3.5 or later.
For NETGEAR WC7520, update to firmware version 2.5.0.46 or later.
For NETGEAR WC7600v1, update to firmware version 6.5.3.5 or later.
For NETGEAR WC7600v2, update to firmware version 6.5.3.5 or later.
For NETGEAR WC9500, update to firmware version 6.5.3.5 or later.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Wc7500
Netgear Wc7520
Netgear Wc7600V1
Netgear Wc7600V2
Netgear Wc9500