VYPR
Unrated severityNVD Advisory· Published Apr 20, 2020· Updated Aug 5, 2024

CVE-2017-18844

CVE-2017-18844

Description

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An administrative credential disclosure vulnerability in several NETGEAR routers allows unauthenticated local access to administrative passwords.

Vulnerability

An administrative credential disclosure vulnerability exists in certain NETGEAR devices, including the R6700v2, R6800, and D7000. The affected firmware versions are R6700v2 and R6800 before 1.1.0.38, and D7000 before 1.0.1.50 [1]. The vulnerability allows disclosure of administrative credentials to an unauthenticated attacker who has local network access.

Exploitation

An unauthenticated attacker with local network access to the affected router can exploit this vulnerability to disclose the administrative credentials [1]. No authentication or user interaction is required. The vector is local, meaning the attacker must be on the same network as the device.

Impact

Successful exploitation leads to the disclosure of administrative credentials, granting the attacker high privileges on the device. This can result in a complete compromise of confidentiality, integrity, and availability, with the attacker potentially gaining full control of the router [1].

Mitigation

NETGEAR has released firmware fixes for all affected models: R6700v2 firmware version 1.1.0.38, R6800 firmware version 1.1.0.38, and D7000 firmware version 1.0.1.50 [1]. Users should download and install the latest firmware from NETGEAR Support as soon as possible. No workarounds are available other than applying the firmware update.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.