6.1

CVE-2017-18866

Certain NETGEAR devices are affected by stored XSS. This affects R9000 before 1.0.2.40, R6100 before 1.0.1.1, 6R7500 before 1.0.0.110, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, WNDR4300v2 before 1.0.0.48, and WNR2000v5 before 1.0.0.58.

Data is provided by the National Vulnerability Database (NVD)
Netgear6r7500 Firmware Version < 1.0.0.110
   Netgear6r7500 Version-
NetgearR6100 Firmware Version < 1.0.1.1
   NetgearR6100 Version-
NetgearR7500 Firmware Version < 1.0.3.20
   NetgearR7500 Versionv2
NetgearR7800 Firmware Version < 1.0.2.36
   NetgearR7800 Version-
NetgearR9000 Firmware Version < 1.0.2.40
   NetgearR9000 Version-
NetgearWndr4300 Firmware Version < 1.0.0.48
   NetgearWndr4300 Versionv2
NetgearWnr2000 Firmware Version < 1.0.0.58
   NetgearWnr2000 Versionv5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.379
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
cve@mitre.org 5.2 2.1 2.7
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.