VYPR
Unrated severityNVD Advisory· Published Apr 23, 2020· Updated Aug 5, 2024

CVE-2017-18739

CVE-2017-18739

Description

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects R6220 before V1.1.0.50, R7800 before V1.0.2.36, WNDR3400v3 before 1.0.1.14, and WNDR3700v5 before V1.1.0.48.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated buffer overflow in several NETGEAR routers allows a nearby attacker to achieve remote code execution or crash the device.

Vulnerability

A pre-authentication buffer overflow vulnerability exists in multiple NETGEAR router models. The affected devices include R6220 (versions before V1.1.0.50), R7800 (versions before V1.0.2.36), WNDR3400v3 (versions before 1.0.1.14), and WNDR3700v5 (versions before V1.1.0.48). The vulnerability is reachable without authentication, meaning no valid credentials or prior access are required [1].

Exploitation

An unauthenticated attacker can exploit this flaw from the local network segment. The attack does not require user interaction or any special privileges. By sending a specially crafted request to the affected device, the attacker triggers a buffer overflow condition [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code with elevated privileges or cause a denial-of-service (device crash). The CVSS v3 score is 8.8 with a vector of CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating high impact on confidentiality, integrity, and availability [1].

Mitigation

NETGEAR has released fixed firmware versions for all affected models. Users should immediately update to the following versions or later: V1.1.0.50 for R6220, V1.0.2.36 for R7800, 1.0.1.14 for WNDR3400v3, and V1.1.0.48 for WNDR3700v5. The fixes are available via NETGEAR Support [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.