CVE-2017-18713

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
24/04/2020
Last modified:
01/05/2020

Description

Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netgear:r7800_firmware:*:*:*:*:*:*:*:* 1.0.2.40 (excluding)
cpe:2.3:h:netgear:r7800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r9000_firmware:*:*:*:*:*:*:*:* 1.0.2.52 (excluding)
cpe:2.3:h:netgear:r9000:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wndr4300_firmware:*:*:*:*:*:*:*:* 1.0.0.48 (excluding)
cpe:2.3:h:netgear:wndr4300:v2:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wndr4500_firmware:*:*:*:*:*:*:*:* 1.0.0.48 (excluding)
cpe:2.3:h:netgear:wndr4500:v3:*:*:*:*:*:*:*
cpe:2.3:o:netgear:d7800_firmware:*:*:*:*:*:*:*:* 1.0.1.28 (excluding)
cpe:2.3:h:netgear:d7800:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r7500_firmware:*:*:*:*:*:*:*:* 1.0.3.20 (excluding)
cpe:2.3:h:netgear:r7500:v2:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6700_firmware:*:*:*:*:*:*:*:* 1.0.1.36 (excluding)
cpe:2.3:h:netgear:r6700:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6900_firmware:*:*:*:*:*:*:*:* 1.0.1.34 (excluding)