CVE-2026-15757
MEDIUMNETGEAR DGND3700v1 - Adjacent Network Command Injection
Title source: manualDescription
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on physical production devices.
References (2)
Core 2
Core References
patch
product
https://www.netgear.com/support/product/dgnd3700v1
Vendor Advisory vendor-advisory
https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory
Scores
CVSS v4
6.3
EPSS
0.0020
EPSS Percentile
10.5%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (1)
NETGEAR/DGND3700v1
< V1.0.0.17
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026