VYPR
Unrated severityNVD Advisory· Published Apr 23, 2020· Updated Aug 5, 2024

CVE-2017-18742

CVE-2017-18742

Description

Certain NETGEAR devices are affected by CSRF. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6250 before 1.0.4.12, R6300v2 before 1.0.4.8, R6700 before 1.0.1.16, R6900 before 1.0.1.16, R7300DST before 1.0.0.54, R7900 before 1.0.1.12, R8000 before 1.0.3.32, and R8500 before 1.0.2.74.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in multiple NETGEAR routers allows attackers to perform unauthorized actions via crafted requests.

Vulnerability

This is a cross-site request forgery (CSRF) vulnerability affecting several NETGEAR router models. The vulnerability exists in the web management interface. Affected models include JR6150 (before 1.0.1.10), R6050 (before 1.0.1.10), R6250 (before 1.0.4.12), R6300v2 (before 1.0.4.8), R6700 (before 1.0.1.16), R6900 (before 1.0.1.16), R7300DST (before 1.0.0.54), R7900 (before 1.0.1.12), R8000 (before 1.0.3.32), and R8500 (before 1.0.2.74) [1]. The vulnerability allows an attacker to trick an authenticated administrator into executing unintended actions.

Exploitation

An attacker can exploit this CSRF vulnerability by crafting a malicious web page or link that, when visited by an authenticated administrator, triggers unauthorized actions on the router's management interface. The attacker does not need authentication but relies on the victim's active session. The attack requires user interaction (the victim must click the link or visit the page) and can be performed remotely over the network [1].

Impact

Successful exploitation allows an attacker to perform arbitrary actions on the affected router with the privileges of the authenticated administrator. This could include changing configuration settings, modifying firewall rules, or other administrative operations, potentially leading to full compromise of the device and network [1]. The CVSS v3 score is 8.8 (High) with vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating high impact on confidentiality, integrity, and availability [1].

Mitigation

NETGEAR has released firmware updates to fix this vulnerability. Users should update to the following versions or later: JR6150 to 1.0.1.10, R6050 to 1.0.1.10, R6250 to 1.0.4.12, R6300v2 to 1.0.4.8, R6700 to 1.0.1.16, R6900 to 1.0.1.16, R7300DST to 1.0.0.54, R7900 to 1.0.1.12, R8000 to 1.0.3.32, and R8500 to 1.0.2.74 [1]. No workarounds are mentioned; updating firmware is the recommended mitigation. The advisory was published in 2020, so patches have been available for some time.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.