VYPR
Unrated severityNVD Advisory· Published Apr 22, 2020· Updated Aug 5, 2024

CVE-2017-18782

CVE-2017-18782

Description

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R6800 before 1.2.0.12, R6900v2 before 1.2.0.12, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF in many NETGEAR routers allows an attacker to perform actions as an authenticated user if the victim visits a malicious page.

Vulnerability

The affected NETGEAR devices are vulnerable to Cross-Site Request Forgery (CSRF). This flaw exists in the web management interface of the following models: D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R6800 before 1.2.0.12, R6900v2 before 1.2.0.12, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44 [1].

Exploitation

To exploit this vulnerability, an attacker must craft a malicious page or link that sends unauthorized commands to a victim's router. The attacker does not need any prior authentication to the router, but the victim must be logged into the router's web interface and then visit the attacker's page. The lack of CSRF tokens or other anti-forgery mechanisms allows the malicious request to be executed as if initiated by the authenticated victim [1].

Impact

A successful CSRF attack could allow an attacker to perform any action available in the router's web interface that the victim is authorized to do. This can include changing DNS settings, altering firewall rules, or upgrading firmware, potentially leading to a full compromise of the device's configuration and network security [1].

Mitigation

NETGEAR has released fixed firmware versions for all affected models as listed in the advisory [1]. Users should upgrade to the specified firmware version or later immediately. The advisory does not list any workaround for unpatched devices [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.