CVE-2017-18851
MEDIUMNETGEAR D8500/R6400/R8300/R8500/R6100 Firmware - Authenticated Command Injection
Title source: llmDescription
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D8500 through 1.0.3.28, R6400 through 1.0.1.22, R6400v2 through 1.0.2.18, R8300 through 1.0.2.94, R8500 through 1.0.2.94, and R6100 through 1.0.1.12.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://kb.netgear.com/000045850/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-and-Modem-Routers-PSV-2017-1207
Scores
CVSS v3
6.7
EPSS
0.0009
EPSS Percentile
24.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-74
Status
published
Products (5)
netgear/d8500_firmware
< 1.0.3.28
netgear/r6100_firmware
< 1.0.1.12
netgear/r6400_firmware
< 1.0.1.22
netgear/r8300_firmware
< 1.0.2.94
netgear/r8500_firmware
< 1.0.2.94
Published
Apr 20, 2020
Tracked Since
Feb 18, 2026