VYPR
Unrated severityNVD Advisory· Published Apr 20, 2020· Updated Aug 5, 2024

CVE-2017-18841

CVE-2017-18841

Description

Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.46, and D7000 before 1.0.1.50.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A command injection flaw in several NETGEAR devices (R6220, R6700v2, R6800, WNDR3700v5, D7000) allows authenticated high-privilege attackers to execute arbitrary commands.

Vulnerability

A command injection vulnerability exists in the firmware of certain NETGEAR devices, including the R6220, R6700v2, R6800, WNDR3700v5, and D7000 models. The flaw affects devices running firmware versions prior to 1.1.0.46 (R6220, WNDR3700v5), 1.1.0.38 (R6700v2, R6800), and 1.0.1.50 (D7000) [1]. The exact component within the firmware is not disclosed, but the vulnerability allows an attacker to inject arbitrary operating system commands.

Exploitation

An attacker must have local access to the device (AV:L) and possess high privileges (PR:H) to exploit this vulnerability. No user interaction is required (UI:N). The attacker can send specially crafted input to the vulnerable component, triggering command injection [1]. The CVSS vector indicates that the attack complexity is low (AC:L), making exploitation straightforward once the necessary access and privileges are obtained.

Impact

Successful exploitation allows the attacker to execute arbitrary commands with high privileges, leading to a full compromise of the device's confidentiality, integrity, and availability (C:H/I:H/A:H). This can result in complete device takeover, enabling data exfiltration, configuration changes, or denial of service [1].

Mitigation

NETGEAR has released firmware updates to address this vulnerability. Users should upgrade to the following fixed versions: R6220 to 1.1.0.46, R6700v2 to 1.1.0.38, R6800 to 1.1.0.38, WNDR3700v5 to 1.1.0.46, and D7000 to 1.0.1.50 [1]. No workarounds are available; installing the latest firmware is the only mitigation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.