VYPR
High severity8.4NVD Advisory· Published Jun 11, 2019· Updated Jun 17, 2026

CVE-2017-18378

CVE-2017-18378

Description

In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:netgear:readynas_surveillance_firmware:*:*:*:*:*:*:arm:*+ 1 more
    • cpe:2.3:o:netgear:readynas_surveillance_firmware:*:*:*:*:*:*:arm:*range: <1.1.4-7
    • cpe:2.3:o:netgear:readynas_surveillance_firmware:*:*:*:*:*:*:x86:*range: <1.4.3-17
  • NETGEAR/ReadyNAS Surveillancedescription
  • Range: <1.4.3-17 x86 and <1.1.4-7 ARM

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.