Vulnerability Name:

CVE-2017-18794 (CCN-180649)

Assigned:2017-04-10
Published:2017-04-10
Updated:2020-04-24
Summary:Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3.54, R8500 before 1.0.2.100, and D6100 before 1.0.0.50_0.0.50.
CVSS v3 Severity:8.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.3 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-74
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-18794

Source: XF
Type: UNKNOWN
netgear-cve201718794-cmd-exec(180649)

Source: CCN
Type: NETGEAR Security Advisory: PSV-2017-0321
Security Advisory for Command Injection Vulnerability on D6100 and Some Routers

Source: CONFIRM
Type: Vendor Advisory
https://kb.netgear.com/000049368/Security-Advisory-for-Command-Injection-Vulnerability-on-D6100-and-Some-Routers-PSV-2017-0321

Vulnerable Configuration:Configuration 1:
  • cpe:/o:netgear:r6300_firmware:*:*:*:*:*:*:*:* (Version < 1.0.4.8_10.0.77)
  • AND
  • cpe:/h:netgear:r6300:v2:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:netgear:r6400_firmware:*:*:*:*:*:*:*:* (Version < 1.0.1.24)
  • AND
  • cpe:/h:netgear:r6400:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:netgear:r6700_firmware:*:*:*:*:*:*:*:* (Version < 1.0.1.26)
  • AND
  • cpe:/h:netgear:r6700:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:netgear:r7000_firmware:*:*:*:*:*:*:*:* (Version < 1.0.9.10)
  • AND
  • cpe:/h:netgear:r7000:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:netgear:r7100lg_firmware:*:*:*:*:*:*:*:* (Version < 1.0.0.32)
  • AND
  • cpe:/h:netgear:r7100lg:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:netgear:r7900_firmware:*:*:*:*:*:*:*:* (Version < 1.0.1.18)
  • AND
  • cpe:/h:netgear:r7900:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:netgear:r8000_firmware:*:*:*:*:*:*:*:* (Version < 1.0.3.54)
  • AND
  • cpe:/h:netgear:r8000:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:netgear:r8500_firmware:*:*:*:*:*:*:*:* (Version < 1.0.2.100)
  • AND
  • cpe:/h:netgear:r8500:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:netgear:d6100_firmware:*:*:*:*:*:*:*:* (Version < 1.0.0.50_0.0.50)
  • AND
  • cpe:/h:netgear:d6100:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:netgear:d6100_firmware:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r7000_firmware:1.0.9:*:*:*:*:*:*:*
  • OR cpe:/h:netgear:r8500:-:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r6300v2_firmware:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r6400_firmware:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r7100lg_firmware:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r6700_firmware:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r7900_firmware:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:netgear:r8000_firmware:1.0.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    netgear r6300 firmware *
    netgear r6300 v2
    netgear r6400 firmware *
    netgear r6400 -
    netgear r6700 firmware *
    netgear r6700 -
    netgear r7000 firmware *
    netgear r7000 -
    netgear r7100lg firmware *
    netgear r7100lg -
    netgear r7900 firmware *
    netgear r7900 -
    netgear r8000 firmware *
    netgear r8000 -
    netgear r8500 firmware *
    netgear r8500 -
    netgear d6100 firmware *
    netgear d6100 -
    netgear d6100 firmware 1.0.0
    netgear r7000 firmware 1.0.9
    netgear r8500 -
    netgear r6300v2 firmware 1.0.4
    netgear r6400 firmware 1.0.1
    netgear r7100lg firmware 1.0.0
    netgear r6700 firmware 1.0.1
    netgear r7900 firmware 1.0.1
    netgear r8000 firmware 1.0.3