VYPR
Unrated severityNVD Advisory· Published Apr 22, 2020· Updated Aug 5, 2024

CVE-2017-18758

CVE-2017-18758

Description

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated stack buffer overflow in multiple NETGEAR routers (R6700v2, R6800, R6900v2) prior to firmware 1.1.0.42 allows high-severity code execution.

Vulnerability

A stack-based buffer overflow vulnerability exists in certain NETGEAR routers, specifically the R6700v2, R6800, and R6900v2 models running firmware versions prior to 1.1.0.42 [1]. The flaw resides in an undisclosed component accessible after authentication, allowing an authenticated user to trigger a buffer overflow on the stack. The vulnerability is tracked as PSV-2017-2157 and affects only the listed models with firmware older than the fixed version [1].

Exploitation

To exploit the vulnerability, an attacker must first have network access (adjacent network, per CVSS vector) and be authenticated to the router's administrative interface [1]. The attacker then sends a crafted request or data that overflows the stack buffer. The CVSS vector indicates no user interaction is required beyond authentication, and the attack does not require prior privileges beyond standard user authentication [1].

Impact

Successful exploitation results in high impact on confidentiality, integrity, and availability. The CVSS v3 score of 8.8 (High) with the vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates that an attacker can achieve arbitrary code execution, full disclosure of sensitive information, and complete compromise of the device [1]. The scope is unchanged, meaning the attacker's control is limited to the affected router [1].

Mitigation

NETGEAR has released fixed firmware version 1.1.0.42 for all affected models (R6700v2, R6800, R6900v2) [1]. Users are strongly recommended to download and install the latest firmware from the NETGEAR Support website. There are no workarounds provided; updating to the patched version is the only mitigation [1]. The affected products are not listed as end-of-life, and this vulnerability is not currently in the CISA Known Exploited Vulnerabilities catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.