SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-18805

Certain NETGEAR devices are affected by command injection.

MEDIUM 6.7EPSS 0.56%

Does this matter?

Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.

Description

Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 before 3.7.4.0, WNAP210v2 before 3.7.4.0, and WNDAP360 before 3.7.4.0.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.56% probability · 45th percentile
CISA KEV
Not listed
Weakness
CWE-74
Affected
netgear/wac510 firmware · netgear/wac120 firmware · netgear/wndap620 firmware · netgear/wnd930 firmware · netgear/wn604 firmware · netgear/wndap660 firmware · netgear/wndap350 firmware · netgear/wnap320 firmware · netgear/wnap210 firmware · netgear/wndap360 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.