7.1

CVE-2017-18863

Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP320 3.5.20.0 and earlier, WNDAP350 3.5.20.0 and earlier, WNDAP360 3.5.20.0 and earlier, WNDAP620 2.0.11 and earlier, WNDAP660 3.5.20.0 and earlier, WND930 2.0.11 and earlier, and WAC120 2.0.7 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgear ≫ Wn604 Firmware Version < 3.3.3
   Netgear ≫ Wn604 Version -
Netgear ≫ Wnap210 Firmware Version < 3.5.20.0
   Netgear ≫ Wnap210 Version v2
Netgear ≫ Wnap320 Firmware Version < 3.5.20.0
   Netgear ≫ Wnap320 Version -
Netgear ≫ Wndap350 Firmware Version < 3.5.20.0
   Netgear ≫ Wndap350 Version -
Netgear ≫ Wndap360 Firmware Version < 3.5.20.0
   Netgear ≫ Wndap360 Version -
Netgear ≫ Wndap620 Firmware Version < 2.0.11
   Netgear ≫ Wndap620 Version -
Netgear ≫ Wndap660 Firmware Version < 3.5.20.0
   Netgear ≫ Wndap660 Version -
Netgear ≫ Wnd930 Firmware Version < 2.0.11
   Netgear ≫ Wnd930 Version -
Netgear ≫ Wac120 Firmware Version < 2.0.7
   Netgear ≫ Wac120 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.397
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:P/A:N
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://kb.netgear.com/000037827/Security-Advisory-for-PHP-Vulnerabilities-on-Wireless-Access-Points-PSV-2017-0517-and-PSV-2016-0258
Vendor Advisory