CVE-2017-18852

HIGH

NETGEAR R7300DST/R8300/R8500/WNDR3400v3 - Cross-Site Request Forgery and Authentication Bypass

Title source: llm
STIX 2.1

Description

Certain NETGEAR devices are affected by CSRF and authentication bypass. This affects R7300DST before 1.0.0.54, R8300 before 1.0.2.100_1.0.82, R8500 before 1.0.2.100_1.0.82, and WNDR3400v3 before 1.0.1.14.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (4)
netgear/r7300dst_firmware < 1.0.0.54
netgear/r8300_firmware < 1.0.2.100_1.0.82
netgear/r8500_firmware < 1.0.2.100_1.0.82
netgear/wndr3400_firmware < 1.0.1.14
Published Apr 20, 2020
Tracked Since Feb 18, 2026