PT-2020-8519 · NetGear · Netgear Wc7600V1+4

Alexander Oleinik

+5

·

Published

2020-04-01

·

Updated

2020-08-24

·

CVE-2018-11106

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: NETGEAR WC7500 versions prior to 6.5.3.5 NETGEAR WC7520 versions prior to 2.5.0.46 NETGEAR WC7600v1 versions prior to 6.5.3.5 NETGEAR WC7600v2 versions prior to 6.5.3.5 NETGEAR WC9500 versions prior to 6.5.3.5
Description: The issue is a pre-authentication command injection in the request handler.php file. This allows for potential exploitation without the need for authentication. The estimated number of potentially affected devices worldwide is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations: For NETGEAR WC7500, update to firmware version 6.5.3.5 or later. For NETGEAR WC7520, update to firmware version 2.5.0.46 or later. For NETGEAR WC7600v1, update to firmware version 6.5.3.5 or later. For NETGEAR WC7600v2, update to firmware version 6.5.3.5 or later. For NETGEAR WC9500, update to firmware version 6.5.3.5 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11106

Affected Products

Netgear Wc7500
Netgear Wc7520
Netgear Wc7600V1
Netgear Wc7600V2
Netgear Wc9500