CVE-2017-18757
Description
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.30, R6100 before 1.0.1.16, R7500 before 1.0.0.116, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.40, WNDR4300v2 before 1.0.0.48, WNDR4300v1 before 1.0.2.90, and WNDR4500v3 before 1.0.0.48.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NETGEAR routers have a security misconfiguration enabling adjacent attackers to cause limited info disclosure and configuration changes.
Vulnerability
A security misconfiguration in the firmware of multiple NETGEAR routers allows unintended access to reserved information or the ability to change the configuration. The affected devices include D7800 before 1.0.1.30, R6100 before 1.0.1.16, R7500 before 1.0.0.116, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.40, WNDR4300v2 before 1.0.0.48, WNDR4300v1 before 1.0.2.90, and WNDR4500v3 before 1.0.0.48 [1].
Exploitation
An attacker on the same local network can exploit this vulnerability without authentication or user interaction. The attack complexity is high, requiring specific conditions or repeated attempts. No privileged access is required, and the attacker does not need to be on the same subnet as the target device [1].
Impact
Successful exploitation results in low confidentiality and integrity impact, meaning the attacker can read reserved information or modify the device configuration. The scope of the impact changes, potentially affecting other components beyond the vulnerable device [1].
Mitigation
NETGEAR has released firmware updates to address this vulnerability. Users should upgrade to the fixed firmware versions as listed: D7800 to 1.0.1.30, R6100 to 1.0.1.16, R7500 to 1.0.0.116, R7500v2 to 1.0.3.20, R7800 to 1.0.2.36, R9000 to 1.0.2.40, WNDR4300v2 to 1.0.0.48, WNDR4300v1 to 1.0.2.90, and WNDR4500v3 to 1.0.0.48 [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.