CVE-2017-18786

EUVD-2017-9877
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.0/AC:L/AV:L/A:H/C:H/I:H/PR:N/S:U/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
netgeard6200_firmware
𝑥
< 1.1.00.24
netgearjnr1010_firmware
𝑥
< 1.1.0.44
netgearjr6150_firmware
𝑥
< 1.0.1.12
netgearjwnr2010_firmware
𝑥
< 1.1.0.44
netgearpr2000_firmware
𝑥
< 1.0.0.20
netgearr6050_firmware
𝑥
< 1.0.1.12
netgearwnr1000_firmware
𝑥
< 1.1.0.44
netgearwnr2020_firmware
𝑥
< 1.1.0.44
netgearwnr2050_firmware
𝑥
< 1.1.0.44
𝑥
= Vulnerable software versions