Junglewise Threat Intelligence

CVE-2026-15757: NETGEAR DGND3700v1 improper input validation

CVE-2026-15757 · Severity: info · CVSS 6.3 · Published 2026-07-14

Vendors: NETGEAR.

Executive brief

A security flaw in the NETGEAR DGND3700v1 router could allow an attacker on the same local WiFi network to send unauthorized commands to the device. This router is a consumer-grade gateway used to provide internet access and local networking. If exploited, an attacker could potentially gain control over the device, leading to unauthorized configuration changes or interception of network traffic.

Technical details

An improper input validation vulnerability (CWE-20) exists in the NETGEAR DGND3700v1 router. The flaw allows an unauthenticated attacker located on the same adjacent network (WiFi) to issue unauthorized commands to the device. This issue was identified in a simulated research environment and has not been confirmed on physical hardware. Successful exploitation could lead to a total loss of confidentiality, integrity, and availability on the affected device. The vulnerability is present in firmware versions up to and including V1.0.0.17.

Affected products

  • NETGEAR DGND3700v1 V1.0.0.17 and earlier

Timeline

  • 2026-07-14: advisory: NVD published the CVE record based on Netgear disclosure.

References