VYPR
Unrated severityNVD Advisory· Published Apr 20, 2020· Updated Aug 5, 2024

CVE-2017-18828

CVE-2017-18828

Description

Certain NETGEAR devices are affected by stored XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in NETGEAR M4300 and M4200 switches before firmware 12.0.2.15 allows authenticated users to inject malicious scripts.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the web management interface of multiple NETGEAR fully managed switch models, including M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, M4300-24X24F, M4300-24X, M4300-48X, and M4200. All devices running firmware versions prior to 12.0.2.15 are affected. The vulnerability allows an authenticated attacker to inject arbitrary script code into a stored configuration parameter or input field that is later rendered to other users [1].

Exploitation

An attacker must have authenticated access to the switch's web-based management interface. The attacker can craft a malicious JavaScript payload and submit it via a vulnerable input field (e.g., a device name, description, or other configuration parameter). The payload is stored on the device and executed when another administrator views the affected page [1].

Impact

Successful exploitation enables the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can lead to session hijacking, defacement of the management interface, or redirection to malicious sites. The CVSS v3 score is 5.2 (Medium), with a vector of AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L, indicating low confidentiality, integrity, and availability impact but requiring high privileges and user interaction [1].

Mitigation

NETGEAR has released firmware version 12.0.2.15 for all affected models. Users should download and install the latest firmware from the NETGEAR Support website as soon as possible. No workarounds are provided; updating to the fixed version is the only recommended mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.