CVE-2017-6862
NETGEAR Multiple Devices Buffer Overflow Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Multiple Devices, fix it now.
CISA required action: Apply updates per vendor instructions.
US federal civilian agencies must remediate by Jun 22, 2022.
Patch status
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations and CISA's required action, limit exposure of affected systems, and watch this record for a patch.
Description
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Affected products
| Product | Vendor | Source |
|---|---|---|
| Multiple Devices | NETGEAR | KEV |
Sources: KEV = CISA Known Exploited Vulnerabilities catalog. Version details have not been published yet.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdateKEV
CVE-2017-6862 scored CVSS 9.8: NETGEAR Multiple Devices, NETGEAR Multiple Devices Buffer Overflow Vulnerability
CISA lists this as exploited in the wild. Unpatched Multiple Devices systems are exposed to active attacks now.
Basis: NIST National Vulnerability Database
1 earlier event is available with a subscription. See plans.
Coverage
We have not published a story about this vulnerability yet.
