Arbitrary File Reading Vulnerability in NETGEAR Routers
CVE-2017-18847

6.2MEDIUM

Key Information:

Vendor
Netgear
Vendor
CVE Published:
20 April 2020

Summary

Certain NETGEAR routers are susceptible to a vulnerability that allows an attacker to read arbitrary files on the device. This could lead to unauthorized access to sensitive information stored in the router's filesystem. The affected models include R6400v2, R7000P/R6900P, R7900, R8300, R8500, and D8500, each with specific firmware versions that must be updated to mitigate the risk. Users are advised to upgrade their devices to the latest firmware as recommended in NETGEAR's security advisory.

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.