CVE-2017-18805
Description
Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 before 3.7.4.0, WNAP210v2 before 3.7.4.0, and WNDAP360 before 3.7.4.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple NETGEAR wireless access points contain a command injection vulnerability allowing authenticated administrators to execute arbitrary commands.
Vulnerability
A command injection vulnerability exists in the web interface of multiple NETGEAR wireless access point models. Affected devices include WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 before 3.7.4.0, WNAP210v2 before 3.7.4.0, and WNDAP360 before 3.7.4.0 [1]. The vulnerability is due to insufficient sanitization of user-supplied input, allowing injection of operating system commands.
Exploitation
Exploitation requires administrator-level access to the device's web-based management interface. An attacker with valid admin credentials can craft a request with malicious input in certain parameters, leading to command execution on the underlying operating system. No user interaction is required beyond the attacker's own actions [1].
Impact
Successful exploitation allows an authenticated attacker to execute arbitrary commands with root privileges on the affected device. This results in full compromise of confidentiality, integrity, and availability (CVSS v3 Base Score 6.7, vector AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) [1].
Mitigation
NETGEAR has released firmware updates to address this vulnerability. Users should upgrade to the following fixed versions or later: WAC510 (1.3.0.10), WAC120 (2.1.4), WNDAP620 (2.1.3), WND930 (2.1.2), WN604 (3.3.7), WNDAP660 (3.7.4.0), WNDAP350 (3.7.4.0), WNAP320 (3.7.4.0), WNAP210v2 (3.7.4.0), and WNDAP360 (3.7.4.0) [1]. No workarounds are provided; updating firmware is the only recommended mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/WAC510description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.