VYPR
Unrated severityNVD Advisory· Published Apr 21, 2020· Updated Aug 5, 2024

CVE-2017-18813

CVE-2017-18813

Description

NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR ReadyNAS OS 6 devices prior to 6.8.0 are vulnerable to stored cross-site scripting (XSS), allowing authenticated attackers to inject malicious scripts.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in NETGEAR ReadyNAS OS 6 devices running firmware versions prior to 6.8.0. The flaw allows an attacker with administrative privileges to inject arbitrary JavaScript or HTML into the web interface, which is then stored and executed in the context of other users' sessions. All ReadyNAS OS 6 models are affected [1].

Exploitation

To exploit this vulnerability, an attacker must have local access to the device and possess high privileges (e.g., administrator). The attacker injects malicious script into a stored field (e.g., share name, description) that is later rendered without proper sanitization. Successful exploitation requires user interaction, such as an administrator viewing the affected page. The CVSS vector indicates a local attack vector with high privileges and user interaction required [1].

Impact

A successful attack leads to low impact on confidentiality, integrity, and availability. The attacker can execute arbitrary script in the context of the victim's browser, potentially stealing session cookies, defacing the interface, or performing actions on behalf of the victim. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component [1].

Mitigation

NETGEAR released firmware version 6.8.0 to address this vulnerability. Users are strongly advised to update their ReadyNAS OS 6 devices to the latest firmware as soon as possible. The update can be obtained from the NETGEAR Support website. No workarounds are provided; the vulnerability is only fixed by upgrading [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.