CVE-2017-18786
Description
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple NETGEAR routers are vulnerable to command injection before specific firmware versions, allowing local attackers to execute arbitrary commands.
Vulnerability
A command injection vulnerability exists in several NETGEAR router models, including D6200, JNR1010v2, JR6150, JWNR2010v5, PR2000, R6050, WNR1000v4, WNR2020, and WNR2050. The affected firmware versions are prior to 1.1.00.24 for D6200, 1.1.0.44 for JNR1010v2, 1.0.1.12 for JR6150, 1.1.0.44 for JWNR2010v5, 1.0.0.20 for PR2000, 1.0.1.12 for R6050, 1.1.0.44 for WNR1000v4, 1.1.0.44 for WNR2020, and 1.1.0.44 for WNR2050 [1]. The bug resides in an unspecified component and can be triggered without authentication, as per the CVSS vector [1].
Exploitation
An attacker with local network access (AV:L) can exploit the vulnerability by sending specially crafted input to a vulnerable interface. No user interaction or privileges are required (PR:N, UI:N) [1]. The command injection allows the attacker to execute arbitrary operating system commands on the device. The exact attack vector or parameter used for injection is not detailed in the available references.
Impact
Successful exploitation results in complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) [1]. The attacker gains the ability to execute arbitrary commands with the privileges of the affected service, potentially leading to full device control, data exfiltration, or denial of service.
Mitigation
NETGEAR has released fixed firmware versions for all affected models, as listed in their security advisory [1]. Users should upgrade to the following firmware versions or later: D6200 to 1.1.00.24, JNR1010v2 to 1.1.0.44, JR6150 to 1.0.1.12, JWNR2010v5 to 1.1.0.44, PR2000 to 1.0.0.20, R6050 to 1.0.1.12, WNR1000v4 to 1.1.0.44, WNR2020 to 1.1.0.44, and WNR2050 to 1.1.0.44 [1]. No workarounds are provided. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
10- NETGEAR/D6200description
- Range: <1.1.0.44
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- kb.netgear.com/000049529/Security-Advisory-for-Command-Injection-on-Some-Routers-PSV-2017-2949mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.