Vulnerability Description
Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3.54, R8500 before 1.0.2.100, and D6100 before 1.0.0.50_0.0.50.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | R6300 Firmware | < 1.0.4.8_10.0.77 |
| Netgear | R6300 | v2 |
| Netgear | R6400 Firmware | < 1.0.1.24 |
| Netgear | R6400 | - |
| Netgear | R6700 Firmware | < 1.0.1.26 |
| Netgear | R6700 | - |
| Netgear | R7000 Firmware | < 1.0.9.10 |
| Netgear | R7000 | - |
| Netgear | R7100Lg Firmware | < 1.0.0.32 |
| Netgear | R7100Lg | - |
| Netgear | R7900 Firmware | < 1.0.1.18 |
| Netgear | R7900 | - |
| Netgear | R8000 Firmware | < 1.0.3.54 |
| Netgear | R8000 | - |
| Netgear | R8500 Firmware | < 1.0.2.100 |
| Netgear | R8500 | - |
| Netgear | D6100 Firmware | < 1.0.0.50_0.0.50 |
| Netgear | D6100 | - |
Related Weaknesses (CWE)
References
- https://kb.netgear.com/000049368/Security-Advisory-for-Command-Injection-VulneraVendor Advisory
- https://kb.netgear.com/000049368/Security-Advisory-for-Command-Injection-VulneraVendor Advisory
FAQ
What is CVE-2017-18794?
CVE-2017-18794 is a vulnerability with a CVSS score of 8.4 (HIGH). Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7...
How severe is CVE-2017-18794?
CVE-2017-18794 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18794?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear R6300 Firmware, Netgear R6300, Netgear R6400 Firmware, Netgear R6400, Netgear R6700 Firmware.