CVE-2017-18775
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
22/04/2020
Last modified:
24/04/2020
Description
Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.42.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:netgear:r6100_firmware:*:*:*:*:*:*:*:* | 1.0.1.12 (excluding) | |
| cpe:2.3:h:netgear:r6100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:r7500_firmware:*:*:*:*:*:*:*:* | 1.0.0.108 (excluding) | |
| cpe:2.3:h:netgear:r7500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wndr3700_firmware:*:*:*:*:*:*:*:* | 1.0.2.86 (excluding) | |
| cpe:2.3:h:netgear:wndr3700:v4:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wndr4300_firmware:*:*:*:*:*:*:*:* | 1.0.2.88 (excluding) | |
| cpe:2.3:h:netgear:wndr4300:v1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wndr4300_firmware:*:*:*:*:*:*:*:* | 1.0.0.48 (excluding) | |
| cpe:2.3:h:netgear:wndr4300:v2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wndr4500_firmware:*:*:*:*:*:*:*:* | 1.0.0.48 (excluding) | |
| cpe:2.3:h:netgear:wndr4500:v3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:netgear:wnr2000_firmware:*:*:*:*:*:*:*:* | 1.0.0.42 (excluding) | |
| cpe:2.3:h:netgear:wnr2000:v5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



