CVE-2017-18789

MEDIUM

NETGEAR Multiple Router Models Firmware - Unauthenticated Sensitive Information Exposure

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6250 before V1.0.4.8, R6400 before V1.0.1.22, R6400v2 before V1.0.2.32, R7100LG before V1.0.0.32, R7300 before V1.0.0.52, R8300 before V1.0.2.94, R8500 before V1.0.2.100, D6220 before V1.0.0.28, D6400 before V1.0.0.60, and D8500 before V1.0.3.29.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 15.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (9)
netgear/d6220_firmware < 1.0.0.28
netgear/d6400_firmware < 1.0.0.60
netgear/d8500_firmware < 1.0.3.29
netgear/r6250_firmware < 1.0.4.8
netgear/r6400_firmware < 1.0.1.22
netgear/r7100lg_firmware < 1.0.0.32
netgear/r7300_firmware < 1.0.0.52
netgear/r8300_firmware < 1.0.2.94
netgear/r8500_firmware < 1.0.2.100
Published Apr 22, 2020
Tracked Since Feb 18, 2026