CVE-2017-18844
Description
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An administrative credential disclosure vulnerability in several NETGEAR routers allows unauthenticated local access to administrative passwords.
Vulnerability
An administrative credential disclosure vulnerability exists in certain NETGEAR devices, including the R6700v2, R6800, and D7000. The affected firmware versions are R6700v2 and R6800 before 1.1.0.38, and D7000 before 1.0.1.50 [1]. The vulnerability allows disclosure of administrative credentials to an unauthenticated attacker who has local network access.
Exploitation
An unauthenticated attacker with local network access to the affected router can exploit this vulnerability to disclose the administrative credentials [1]. No authentication or user interaction is required. The vector is local, meaning the attacker must be on the same network as the device.
Impact
Successful exploitation leads to the disclosure of administrative credentials, granting the attacker high privileges on the device. This can result in a complete compromise of confidentiality, integrity, and availability, with the attacker potentially gaining full control of the router [1].
Mitigation
NETGEAR has released firmware fixes for all affected models: R6700v2 firmware version 1.1.0.38, R6800 firmware version 1.1.0.38, and D7000 firmware version 1.0.1.50 [1]. Users should download and install the latest firmware from NETGEAR Support as soon as possible. No workarounds are available other than applying the firmware update.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- NETGEAR/R6700v2description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.