VYPR
Unrated severityNVD Advisory· Published Apr 24, 2020· Updated Aug 5, 2024

CVE-2017-18727

CVE-2017-18727

Description

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A pre-authentication stack buffer overflow in several NETGEAR routers allows an unauthenticated attacker on the local network to execute arbitrary code.

Vulnerability

A stack-based buffer overflow exists in the pre-authentication code of multiple NETGEAR routers. The vulnerability affects the following models and firmware versions: D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42. An unauthenticated attacker can trigger the overflow by sending a specially crafted request to the device, without requiring any prior authentication or user interaction [1].

Exploitation

An attacker must be on the same local network (adjacent network) as the target device. No authentication is needed. The attacker sends a malicious network packet to a vulnerable service listening on the router. The packet contains data that overflows a stack buffer, overwriting critical memory regions. The attack does not require any user interaction or special privileges [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code with high privileges (likely root). This leads to a full compromise of the device, including disclosure of sensitive information, modification of device configuration, and denial of service. The CVSS v3 score is 8.8 (High) with vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [1].

Mitigation

NETGEAR has released fixed firmware versions: D6200 firmware 1.1.00.24, R6700v2 firmware 1.1.0.42, R6800 firmware 1.1.0.42, and R6900v2 firmware 1.1.0.42. Users should download and install the latest firmware from the NETGEAR Support website. No workarounds are provided; updating to the patched version is the only mitigation [1]. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.