Junglewise Threat Intelligence

CVE-2017-6862: NETGEAR Multiple Devices Buffer Overflow Vulnerability

CVE-2017-6862 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-08

Technologies: NETGEAR WNR2000v4, Geovision Multiple Devices, NETGEAR WNR2000v3, NETGEAR WNR2000v5. Vendors: NETGEAR, Geovision.

Executive brief

Multiple NETGEAR WNR2000 router models are vulnerable to a buffer overflow in the administration web application. This flaw allows unauthenticated attackers to bypass authentication and achieve remote code execution via a malicious parameter.

Affected products

  • NETGEAR WNR2000v3 before 1.1.2.14
  • NETGEAR WNR2000v4 before 1.0.0.66
  • NETGEAR WNR2000v5 before 1.0.0.42

Timeline

  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: disclosed

Related threats