CVE-2017-18786

Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AC:L/AV:L/A:H/C:H/I:H/PR:N/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
netgeard6200_firmware
𝑥
< 1.1.00.24
netgearjnr1010_firmware
𝑥
< 1.1.0.44
netgearjr6150_firmware
𝑥
< 1.0.1.12
netgearjwnr2010_firmware
𝑥
< 1.1.0.44
netgearpr2000_firmware
𝑥
< 1.0.0.20
netgearr6050_firmware
𝑥
< 1.0.1.12
netgearwnr1000_firmware
𝑥
< 1.1.0.44
netgearwnr2020_firmware
𝑥
< 1.1.0.44
netgearwnr2050_firmware
𝑥
< 1.1.0.44
𝑥
= Vulnerable software versions