CVE-2017-18736
Description
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, and WNDR3700v5 before 1.1.0.48.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Pre-authentication command injection in multiple NETGEAR routers allows unauthenticated attackers on the local network to execute arbitrary commands.
Vulnerability
A pre-authentication command injection vulnerability exists in the web interface of several NETGEAR router models. The flaw allows an unauthenticated attacker to inject arbitrary operating system commands through a crafted HTTP request. Affected models include JR6150 before firmware version 1.0.1.10, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, and WNDR3700v5 before 1.1.0.48 [1].
Exploitation
An attacker must be on the same local network as the target router (adjacent network) and does not require any authentication. The attacker sends a specially crafted HTTP request to the router's web interface, which fails to properly sanitize user input before passing it to a system command. No user interaction is needed [1].
Impact
Successful exploitation allows the attacker to execute arbitrary commands on the router with root privileges. This can lead to full compromise of the device, including disclosure of sensitive information, modification of device configuration, and potential use as a pivot point for further network attacks. The CVSS v3 score is 8.8 (High) with vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [1].
Mitigation
NETGEAR has released fixed firmware versions for all affected models: JR6150 firmware 1.0.1.10, R6050 firmware 1.0.1.10, R6220 firmware 1.1.0.50, R6700v2 firmware 1.2.0.4, R6800 firmware 1.2.0.4, R6900v2 firmware 1.2.0.4, and WNDR3700v5 firmware 1.1.0.48. Users should update to the latest firmware via the NETGEAR Support website. No workarounds are available [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8- NETGEAR/devicesdescription
- Range: <1.1.0.48
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.