Cross-Site Request Forgery Vulnerability in NETGEAR Routers
CVE-2017-18708
8.8HIGH
Summary
Certain NETGEAR devices, specifically the R8300 and R8500 routers, are susceptible to a Cross-Site Request Forgery (CSRF) attack. This vulnerability allows an attacker to send unauthorized commands from a user’s web browser, which could potentially compromise the integrity of the device's settings. Users are encouraged to update to firmware version 1.0.2.94 or later to mitigate this security issue.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved