CVE-2017-18822
Description
Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A vertical privilege escalation vulnerability in NETGEAR fully managed switches allows low-privileged users to gain administrative access.
Vulnerability
A vertical privilege escalation vulnerability exists in multiple NETGEAR fully managed switch models, including M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, M4300-24X24F, M4300-24X, M4300-48X, and M4200, running firmware versions prior to 12.0.2.15. The flaw allows a user with low privileges to escalate their privileges to a higher level, such as administrative access. The exact mechanism is not detailed in the available references, but the vulnerability is classified as a vertical privilege escalation [1].
Exploitation
An attacker must have local access to the affected device with low-privileged credentials (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). No user interaction is required. The attacker can exploit the vulnerability by leveraging the low-privileged account to perform actions that grant higher privileges, though the specific steps are not disclosed in the advisory [1].
Impact
Successful exploitation allows the attacker to gain elevated privileges, potentially leading to full administrative control over the switch. This results in a complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) of the device and its managed network traffic. The CVSS v3 base score is 7.8 (High) [1].
Mitigation
NETGEAR has released firmware version 12.0.2.15 to address this vulnerability for all affected models. Users are strongly advised to download and install the latest firmware from the NETGEAR Support website. No workarounds are provided, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/M4300-28Gdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.