CVE-2017-18732Improper Authentication in Netgear Plw1000 Firmware

Severity
8.8HIGHNVD
EPSS
1.0%
top 23.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateMay 24

Description

Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, PLW1000v2 before 1.0.0.14, and PLW1010v2 before 1.0.0.14.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDnetgear/r6300_firmware< 1.0.4.8
NVDnetgear/plw1000_firmware< 1.0.0.14
NVDnetgear/plw1010_firmware< 1.0.0.14

🔴Vulnerability Details

2
GHSA
GHSA-phvj-38w6-cv36: Certain NETGEAR devices are affected by authentication bypass2022-05-24
CVEList
CVE-2017-18732: Certain NETGEAR devices are affected by authentication bypass2020-04-23
CVE-2017-18732 — Improper Authentication in Netgear | cvebase