8.8

CVE-2017-18775

Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.42.

Data is provided by the National Vulnerability Database (NVD)
NetgearR6100 Firmware Version < 1.0.1.12
   NetgearR6100 Version-
NetgearR7500 Firmware Version < 1.0.0.108
   NetgearR7500 Version-
NetgearWndr3700 Firmware Version < 1.0.2.86
   NetgearWndr3700 Versionv4
NetgearWndr4300 Firmware Version < 1.0.2.88
   NetgearWndr4300 Versionv1
NetgearWndr4300 Firmware Version < 1.0.0.48
   NetgearWndr4300 Versionv2
NetgearWndr4500 Firmware Version < 1.0.0.48
   NetgearWndr4500 Versionv3
NetgearWnr2000 Firmware Version < 1.0.0.42
   NetgearWnr2000 Versionv5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.424
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
cve@mitre.org 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.