VYPR
Unrated severityNVD Advisory· Published Apr 24, 2020· Updated Aug 5, 2024

CVE-2017-18718

CVE-2017-18718

Description

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A pre-authentication stack overflow in multiple NETGEAR routers allows unauthenticated attackers to execute arbitrary code.

Vulnerability

A stack-based buffer overflow exists in the pre-authentication code path of several NETGEAR routers. The vulnerability affects the following models running firmware versions prior to the indicated fixed release: D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42. An unauthenticated attacker can trigger the overflow by sending a specially crafted packet to the device, as the vulnerable code is reachable without any prior authentication [1].

Exploitation

An attacker must be on the same network (adjacent) to exploit this vulnerability, as indicated by the CVSS vector (AV:A). No authentication or user interaction is required. The attacker sends a malicious network packet to the target device, which triggers the stack overflow in the pre-authentication processing logic [1].

Impact

Successful exploitation allows the attacker to achieve arbitrary code execution on the device. The CVSS v3 score of 8.8 (High) with impacts to Confidentiality, Integrity, and Availability all rated as High indicates that the attacker can gain full control of the affected router, potentially leading to data disclosure, device manipulation, or denial of service [1].

Mitigation

NETGEAR has released fixed firmware versions for all affected models: D6200 firmware version 1.1.00.24, R6700v2 firmware version 1.1.0.42, R6800 firmware version 1.1.0.42, and R6900v2 firmware version 1.1.0.42. Users should update to the latest firmware as soon as possible. No workarounds are provided; the only mitigation is applying the firmware update [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.