CVE-2017-18850 describes an authentication bypass vulnerability affecting numerous NETGEAR router models, including the D6220, R7000, and R8500, across various firmware versions. This high-severity flaw (CVSS 8.4) allows an unauthenticated attacker to bypass security mechanisms, potentially leading to full compromise of the affected device. While no public exploits or active exploitation have been observed, the vulnerability's ease of exploitation and significant impact warrant prompt patching. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.26CPE matchmatch criteria | cpe:2.3:o:netgear:d6220_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.60CPE matchmatch criteria | cpe:2.3:o:netgear:d6400_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.3.29CPE matchmatch criteria | cpe:2.3:o:netgear:d8500_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.4.12CPE matchmatch criteria | cpe:2.3:o:netgear:r6250_firmware:*:*:*:*:*:*:*:* | ||
< 1.01.24CPE matchmatch criteria | cpe:2.3:o:netgear:r6400_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.