Vulnerability Details CVE-2017-6862
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.587
EPSS Ranking 98.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Proposed Action
Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.
Ransomware Campaign
Unknown
Products affected by CVE-2017-6862
-
cpe:2.3:h:netgear:wnr2000v3:-
-
cpe:2.3:h:netgear:wnr2000v4:-
-
cpe:2.3:h:netgear:wnr2000v5:-
-
cpe:2.3:o:netgear:wnr2000v3_firmware:-
-
cpe:2.3:o:netgear:wnr2000v3_firmware:1.1.2.13
-
cpe:2.3:o:netgear:wnr2000v4_firmware:-
-
cpe:2.3:o:netgear:wnr2000v4_firmware:1.0.0.65
-
cpe:2.3:o:netgear:wnr2000v5_firmware:-
-
cpe:2.3:o:netgear:wnr2000v5_firmware:1.0.0.34
-
cpe:2.3:o:netgear:wnr2000v5_firmware:1.0.0.41