CVE-2017-18841
Description
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.46, and D7000 before 1.0.1.50.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A command injection flaw in several NETGEAR devices (R6220, R6700v2, R6800, WNDR3700v5, D7000) allows authenticated high-privilege attackers to execute arbitrary commands.
Vulnerability
A command injection vulnerability exists in the firmware of certain NETGEAR devices, including the R6220, R6700v2, R6800, WNDR3700v5, and D7000 models. The flaw affects devices running firmware versions prior to 1.1.0.46 (R6220, WNDR3700v5), 1.1.0.38 (R6700v2, R6800), and 1.0.1.50 (D7000) [1]. The exact component within the firmware is not disclosed, but the vulnerability allows an attacker to inject arbitrary operating system commands.
Exploitation
An attacker must have local access to the device (AV:L) and possess high privileges (PR:H) to exploit this vulnerability. No user interaction is required (UI:N). The attacker can send specially crafted input to the vulnerable component, triggering command injection [1]. The CVSS vector indicates that the attack complexity is low (AC:L), making exploitation straightforward once the necessary access and privileges are obtained.
Impact
Successful exploitation allows the attacker to execute arbitrary commands with high privileges, leading to a full compromise of the device's confidentiality, integrity, and availability (C:H/I:H/A:H). This can result in complete device takeover, enabling data exfiltration, configuration changes, or denial of service [1].
Mitigation
NETGEAR has released firmware updates to address this vulnerability. Users should upgrade to the following fixed versions: R6220 to 1.1.0.46, R6700v2 to 1.1.0.38, R6800 to 1.1.0.38, WNDR3700v5 to 1.1.0.46, and D7000 to 1.0.1.50 [1]. No workarounds are available; installing the latest firmware is the only mitigation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/R6220description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.