VYPR
Unrated severityNVD Advisory· Published Apr 21, 2020· Updated Aug 5, 2024

CVE-2017-18809

CVE-2017-18809

Description

NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR ReadyNAS OS 6 devices prior to 6.8.0 are vulnerable to stored cross-site scripting (XSS).

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in NETGEAR ReadyNAS OS 6 devices running firmware versions prior to 6.8.0. The vulnerability allows an attacker to inject malicious scripts that are stored on the device and later executed in the context of the affected application. The issue affects all ReadyNAS OS 6 series models [1].

Exploitation

Exploitation requires an attacker to have high privileges (e.g., administrator access) and relies on user interaction. An authenticated attacker with high privileges can inject malicious script code into input fields that are not properly sanitized. When another user (or the same user) accesses the affected page, the stored script executes. The CVSS vector indicates the attack vector is local, complexity is low, and user interaction is required [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to disclosure of sensitive information, modification of content, or limited access to other application features. The CVSS v3 score is 5.2 (Medium) with impacts to confidentiality, integrity, and availability all rated as low [1].

Mitigation

NETGEAR has released firmware version 6.8.0 which addresses this vulnerability. Users are strongly recommended to download and install the latest firmware from the NETGEAR Support website. No workarounds are documented [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.