CVE-2017-18747
Description
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6000 before 1.0.0.24, EX6130 before 1.0.0.16, EX6400 before 1.0.1.60, EX7000 before 1.0.0.50, EX7300 before 1.0.1.60, and WN2500RPv2 before 1.0.1.46.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A security misconfiguration in several NETGEAR range extenders allows an attacker on the local network to fully compromise the device without authentication.
Vulnerability
A security misconfiguration affects several NETGEAR range extender models, including EX3700, EX3800, EX6000, EX6130, EX6400, EX7000, EX7300, and WN2500RPv2, before the firmware versions listed in the advisory [1]. The exact configuration weakness is not publicly detailed, but the vulnerability allows an attacker to impact the device's security settings [1].
Exploitation
The CVSS vector indicates that an attacker with adjacent network access can exploit the vulnerability without credentials or user interaction (CVSS:3.0/AV:A/AC:L/PR:N/UI:N) [1]. The specific steps are not documented, but the misconfiguration allows unauthorized access to device functionality.
Impact
Successful exploitation results in high impact on confidentiality, integrity, and availability (CVSS:3.0/C:H/I:H/A:H) [1]. An attacker gains full control of the device, potentially reading sensitive data, modifying configuration, or causing denial of service. The compromise is at the device level with no privilege escalation needed.
Mitigation
NETGEAR has released firmware updates to fix the vulnerability. Affected devices should be upgraded to the following versions or later: EX3700/EX3800 to 1.0.0.64, EX6000 to 1.0.0.24, EX6130 to 1.0.0.16, EX6400/EX7300 to 1.0.1.60, EX7000 to 1.0.0.50, and WN2500RPv2 to 1.0.1.46 [1]. No workarounds are available; installing the latest firmware is the only remedy.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/EX3700description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.