| Vulnerability Name: | CVE-2017-18851 (CCN-138836) | ||||||||||||
| Assigned: | 2018-02-07 | ||||||||||||
| Published: | 2018-02-07 | ||||||||||||
| Updated: | 2020-04-23 | ||||||||||||
| Summary: | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D8500 through 1.0.3.28, R6400 through 1.0.1.22, R6400v2 through 1.0.2.18, R8300 through 1.0.2.94, R8500 through 1.0.2.94, and R6100 through 1.0.1.12. | ||||||||||||
| CVSS v3 Severity: | 6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-74 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-18851 Source: XF Type: UNKNOWN netgear-r8500router-cmd-exec(138836) Source: CCN Type: NETGEAR Security Advisory: PSV-2017-1207 Security Advisory for Post-Authentication Command Injection on Some Routers and Modem Routers Source: CONFIRM Type: Vendor Advisory https://kb.netgear.com/000045850/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Modem-Routers-PSV-2017-1207 Source: CCN Type: Trustwave SpiderLabs Security Advisory TWSL2018-003 Vulnerabilities in NETGEAR R8500 router firmware | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration 6: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||