MEDIUM · 6.5

CVE-2017-18853

Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and ear...

Vulnerability Description

Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and earlier, R6400v2 1.0.2.18 and earlier, R6700 1.0.1.22 and earlier, R6900 1.0.1.20 and earlier, R7000 1.0.7.10 and earlier, R7000P 1.0.0.58 and earlier, R7100LG 1.0.0.28 and earlier, R7300DST 1.0.0.52 and earlier, R7900 1.0.1.12 and earlier, R8000 1.0.3.46 and earlier, R8300 1.0.2.86 and earlier, R8500 1.0.2.86 and earlier, WNDR3400v3 1.0.1.8 and earlier, and WNDR4500v2 1.0.0.62 and earlier.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NetgearD8500 Firmware<= 1.0.3.27
NetgearD8500-
NetgearDgn2200 Firmware<= 1.0.0.82
NetgearDgn2200v4
NetgearR6300 Firmware<= 1.0.4.06
NetgearR6300v2
NetgearR6400 Firmware<= 1.0.1.20
NetgearR6400-
NetgearR6700 Firmware<= 1.0.1.22
NetgearR6700-
NetgearR6900 Firmware<= 1.0.1.20
NetgearR6900-
NetgearR7000 Firmware<= 1.0.7.10
NetgearR7000-
NetgearR7000P Firmware<= 1.0.0.58
NetgearR7000P-
NetgearR7100Lg Firmware<= 1.0.0.28
NetgearR7100Lg-
NetgearR7300Dst Firmware<= 1.0.0.52
NetgearR7300Dst-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-18853?

CVE-2017-18853 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and ear...

How severe is CVE-2017-18853?

CVE-2017-18853 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-18853?

Check the references section above for vendor advisories and patch information. Affected products include: Netgear D8500 Firmware, Netgear D8500, Netgear Dgn2200 Firmware, Netgear Dgn2200, Netgear R6300 Firmware.