CVE-2026-15757

MEDIUM

NETGEAR DGND3700v1 - Adjacent Network Command Injection

Title source: manual
STIX 2.1

Description

A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on physical production devices.

References (2)

Core 2

Scores

CVSS v4 6.3
EPSS 0.0020
EPSS Percentile 10.5%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
NETGEAR/DGND3700v1 < V1.0.0.17
Published Jul 14, 2026
Tracked Since Jul 14, 2026