CVE-2017-18782
Description
Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R6800 before 1.2.0.12, R6900v2 before 1.2.0.12, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF in many NETGEAR routers allows an attacker to perform actions as an authenticated user if the victim visits a malicious page.
Vulnerability
The affected NETGEAR devices are vulnerable to Cross-Site Request Forgery (CSRF). This flaw exists in the web management interface of the following models: D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R6800 before 1.2.0.12, R6900v2 before 1.2.0.12, WNDR3700v5 before 1.1.0.50, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44 [1].
Exploitation
To exploit this vulnerability, an attacker must craft a malicious page or link that sends unauthorized commands to a victim's router. The attacker does not need any prior authentication to the router, but the victim must be logged into the router's web interface and then visit the attacker's page. The lack of CSRF tokens or other anti-forgery mechanisms allows the malicious request to be executed as if initiated by the authenticated victim [1].
Impact
A successful CSRF attack could allow an attacker to perform any action available in the router's web interface that the victim is authorized to do. This can include changing DNS settings, altering firewall rules, or upgrading firmware, potentially leading to a full compromise of the device's configuration and network security [1].
Mitigation
NETGEAR has released fixed firmware versions for all affected models as listed in the advisory [1]. Users should upgrade to the specified firmware version or later immediately. The advisory does not list any workaround for unpatched devices [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/NETGEAR devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.