VYPR
Unrated severityNVD Advisory· Published Apr 21, 2020· Updated Aug 5, 2024

CVE-2017-18807

CVE-2017-18807

Description

NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR ReadyNAS OS 6 devices prior to 6.8.0 are vulnerable to stored XSS via unspecified vectors.

Vulnerability

Stored cross-site scripting (XSS) vulnerability affects all NETGEAR ReadyNAS OS 6 devices running firmware versions prior to 6.8.0 [1]. The vulnerability allows an authenticated administrator to inject arbitrary web script or HTML into the device's web interface, which is stored and later executed in the context of another user's session.

Exploitation

Exploitation requires an authenticated attacker with administrative privileges on the ReadyNAS device. The attacker must have the ability to input data that is subsequently stored and rendered by the web interface without proper sanitization [1]. The exact input vector is not disclosed in the available reference, but the CVSS vector (AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L) indicates local access, low complexity, high privileges, and user interaction required for the attack to succeed [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the web interface of another authenticated user, potentially leading to low-level compromise of confidentiality, integrity, and availability of information displayed or processed by the device's management interface [1]. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component.

Mitigation

NETGEAR has released firmware version 6.8.0 to address this vulnerability [1]. Users are strongly recommended to download and install the latest firmware for their specific ReadyNAS OS 6 model from NETGEAR Support [1]. No workarounds are provided, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities Catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.