VYPR
Unrated severityNVD Advisory· Published Apr 21, 2020· Updated Aug 5, 2024

CVE-2017-18805

CVE-2017-18805

Description

Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 before 3.7.4.0, WNAP210v2 before 3.7.4.0, and WNDAP360 before 3.7.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple NETGEAR wireless access points contain a command injection vulnerability allowing authenticated administrators to execute arbitrary commands.

Vulnerability

A command injection vulnerability exists in the web interface of multiple NETGEAR wireless access point models. Affected devices include WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 before 3.7.4.0, WNAP210v2 before 3.7.4.0, and WNDAP360 before 3.7.4.0 [1]. The vulnerability is due to insufficient sanitization of user-supplied input, allowing injection of operating system commands.

Exploitation

Exploitation requires administrator-level access to the device's web-based management interface. An attacker with valid admin credentials can craft a request with malicious input in certain parameters, leading to command execution on the underlying operating system. No user interaction is required beyond the attacker's own actions [1].

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary commands with root privileges on the affected device. This results in full compromise of confidentiality, integrity, and availability (CVSS v3 Base Score 6.7, vector AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) [1].

Mitigation

NETGEAR has released firmware updates to address this vulnerability. Users should upgrade to the following fixed versions or later: WAC510 (1.3.0.10), WAC120 (2.1.4), WNDAP620 (2.1.3), WND930 (2.1.2), WN604 (3.3.7), WNDAP660 (3.7.4.0), WNDAP350 (3.7.4.0), WNAP320 (3.7.4.0), WNAP210v2 (3.7.4.0), and WNDAP360 (3.7.4.0) [1]. No workarounds are provided; updating firmware is the only recommended mitigation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.