Cross-Site Request Forgery Vulnerability in NETGEAR Routers
CVE-2017-18708

8.8HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
24 April 2020

Summary

Certain NETGEAR devices, specifically the R8300 and R8500 routers, are susceptible to a Cross-Site Request Forgery (CSRF) attack. This vulnerability allows an attacker to send unauthorized commands from a user’s web browser, which could potentially compromise the integrity of the device's settings. Users are encouraged to update to firmware version 1.0.2.94 or later to mitigate this security issue.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.