CVE-2017-18863
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.8 / Impact: 5.2
Source: NVD
Description
Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP320 3.5.20.0 and earlier, WNDAP350 3.5.20.0 and earlier, WNDAP360 3.5.20.0 and earlier, WNDAP620 2.0.11 and earlier, WNDAP660 3.5.20.0 and earlier, WND930 2.0.11 and earlier, and WAC120 2.0.7 and earlier.
Affected (9)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.3 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wn604 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.20.0 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wnap210 | Version v2 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.20.0 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wnap320 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.20.0 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap350 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.20.0 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap360 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.11 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap620 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.5.20.0 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wndap660 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.11 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wnd930 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Wac120 | All versions |
References (2)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.