VYPR
Unrated severityNVD Advisory· Published Apr 24, 2020· Updated Aug 5, 2024

CVE-2017-18712

CVE-2017-18712

Description

Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR routers allow an adjacent attacker to read arbitrary files; firmware updates fix eight model families.

Vulnerability

An arbitrary file read vulnerability exists in the web server of multiple NETGEAR router and gateway models. An attacker can read sensitive files from the device's filesystem without authentication. Affected models include: D7800 before firmware version 1.0.1.28, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48 [1].

Exploitation

An attacker must be on the same local network (adjacent access) to reach the vulnerable web interface. No authentication or user interaction is required. The attacker sends a crafted HTTP request to read arbitrary files from the device's filesystem [1].

Impact

Successful exploitation allows the attacker to read arbitrary files, leading to the disclosure of confidential information stored on the device (e.g., configuration files, credentials, or other sensitive data). The confidentiality of the device is compromised; the CVSS v3 base score is 6.5 (Medium) [1].

Mitigation

NETGEAR has released fixed firmware versions for all affected models: D7800 1.0.1.28, R6100 1.0.1.20, R7500 1.0.0.118, R7500v2 1.0.3.20, R7800 1.0.2.40, R9000 1.0.2.52, WNDR4300v2 1.0.0.48, and WNDR4500v3 1.0.0.48. Users should update to these versions as soon as possible [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.