VYPR
Unrated severityNVD Advisory· Published Apr 22, 2020· Updated Aug 5, 2024

CVE-2017-18776

CVE-2017-18776

Description

Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108, R7500v2 before 1.0.3.10, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, WNR1000v4 before 1.1.0.40, WNR2000v5 before 1.0.0.42, WNR2020 before 1.1.0.40, and WNR2050 before 1.1.0.40.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authentication bypass vulnerability in multiple NETGEAR devices allows unauthenticated access; fixed in firmware updates.

Vulnerability

An authentication bypass vulnerability exists in multiple NETGEAR routers and gateways. Affected devices include D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108, R7500v2 before 1.0.3.10, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, WNR1000v4 before 1.1.0.40, WNR2000v5 before 1.0.0.42, WNR2020 before 1.1.0.40, and WNR2050 before 1.1.0.40 [1]. The specific code path and conditions for exploitation are not disclosed.

Exploitation

An attacker can exploit this vulnerability to bypass authentication mechanisms on the affected devices. The advisory does not specify required network position or user interaction, but given the nature of authentication bypass, it is likely exploitable remotely without credentials [1].

Impact

Successful exploitation allows an attacker to bypass authentication and gain unauthorized access to the device's administrative interface or other protected functions. This could lead to full compromise of the device's settings and network [1].

Mitigation

NETGEAR has released firmware updates to fix this vulnerability. Users should update to the following versions or later: D6100 V1.0.0.55, D7000 V1.0.1.50, D7800 V1.0.1.24, JNR1010v2 1.1.0.40, JWNR2010v5 1.1.0.40, R6100 1.0.1.12, R6220 1.1.0.50, R7500 1.0.0.108, R7500v2 1.0.3.10, WNDR4300v1 1.0.2.88, WNDR4300v2 1.0.0.48, WNDR4500v3 1.0.0.48, WNR1000v4 1.1.0.40, WNR2000v5 1.0.0.42, WNR2020 1.1.0.40, and WNR2050 1.1.0.40 [1]. No workarounds are provided; updating firmware is the recommended action.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.