VYPR
Unrated severityNVD Advisory· Published Apr 20, 2020· Updated Aug 5, 2024

CVE-2017-18831

CVE-2017-18831

Description

Certain NETGEAR devices are affected by stored XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NETGEAR fully managed switches before firmware 12.0.2.15 are vulnerable to stored cross-site scripting (XSS), allowing an authenticated attacker to execute arbitrary script code.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in multiple NETGEAR fully managed switch models. Affected devices include M4300-28G, M4300-52G, M4300-28G-POE+, M4300-52G-POE+, M4300-8X8F, M4300-12X12F, M4300-24X24F, M4300-24X, M4300-48X, and M4200, all running firmware versions prior to 12.0.2.15 [1]. The vulnerability allows an authenticated user with local access to inject malicious script code that is stored on the device.

Exploitation

To exploit this vulnerability, an attacker must have valid credentials and local network access to the affected switch. The attacker can inject a script payload through a vulnerable input field in the device's management interface. The stored script then executes in the context of the switch's web interface whenever another authenticated user, including an administrator, accesses the affected page. The CVSS v3 vector indicates the attack vector is local, requires low privileges, and does not require user interaction (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) [1].

Impact

Successful exploitation enables an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user. This can lead to session hijacking, defacement, or theft of sensitive information. The CVSS score of 7.8 (High) reflects the potential for high confidentiality, integrity, and availability impact, with scope change meaning the vulnerable component impacts resources beyond its security scope [1].

Mitigation

NETGEAR released firmware version 12.0.2.15 to fix this vulnerability [1]. Users must download and install the latest firmware from the NETGEAR support site for each affected model. No workaround is available; updating to 12.0.2.15 or later eliminates the stored XSS vulnerability.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.