SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2017-6862

NETGEAR Multiple Devices Buffer Overflow Vulnerability

KEVCRITICAL 9.8EPSS 42.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
42.70% probability · 99th percentile
CISA KEV
Listed 8 June 2022 · due 22 June 2022
Weakness
CWE-120
Affected
netgear/wnr2000 firmware
Source
a2826606-91e7-4eb6-899e-8484bd4575d5

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-6862

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.