CVE-2017-18860

HIGHCVSS 7.7/10EPSS 0.52%

Last modified

CVE-2017-18860 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and earlier, GS716Tv3 6.3.1.16 and earlier, GS724Tv3 5.4.2.27 and earlier, GS724Tv4 6.3.1.16 and earlier, GS728TPSB 5.3.0.29 and earlier, GS728TSB 5.3.0.29 and earlier, GS728TXS 6.1.0.35 and earlier, GS748Tv4 5.4.2.27 and earlier, GS748Tv5 6.3.1.16 and earlier, GS752TPSB 5.3.0.29 and earlier, GS752TSB 5.3.0.29 and earlier, GS752TXS 6.1.0.35 and earlier, M4200 12.0.2.10 and earlier, M4300 12.0.2.10 and earlier, M5300 11.0.0.28 and earlier, M6100 11.0.0.28 and earlier, M7100 11.0.0.28 and earlier, S3300 6.6.1.4 and earlier, XS708T 6.6.0.11 and earlier, XS712T 6.1.0.34 and earlier, and XS716T 6.6.0.11 and earlier.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.

Description

Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and earlier, GS716Tv3 6.3.1.16 and earlier, GS724Tv3 5.4.2.27 and earlier, GS724Tv4 6.3.1.16 and earlier, GS728TPSB 5.3.0.29 and earlier, GS728TSB 5.3.0.29 and earlier, GS728TXS 6.1.0.35 and earlier, GS748Tv4 5.4.2.27 and earlier, GS748Tv5 6.3.1.16 and earlier, GS752TPSB 5.3.0.29 and earlier, GS752TSB 5.3.0.29 and earlier, GS752TXS 6.1.0.35 and earlier, M4200 12.0.2.10 and earlier, M4300 12.0.2.10 and earlier, M5300 11.0.0.28 and earlier, M6100 11.0.0.28 and earlier, M7100 11.0.0.28 and earlier, S3300 6.6.1.4 and earlier, XS708T 6.6.0.11 and earlier, XS712T 6.1.0.34 and earlier, and XS716T 6.6.0.11 and earlier.

Metrics

CVSS 3.1
7.7/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS Probability
0.52%

40.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetgearFs752tp Firmware<= 5.4.2.19
NetgearGs108t Firmware<= 5.4.2.29
NetgearGs110tp Firmware<= 5.4.2.29
NetgearGs418tpp Firmware<= 6.6.2.6
NetgearGs510tlp Firmware<= 6.6.2.6
NetgearGs510tp Firmware<= 5.04.2.27
NetgearGs510tpp Firmware<= 6.6.2.6
NetgearGs716t Firmware<= 5.4.2.27
NetgearGs716t Firmware<= 6.3.1.16
NetgearGs724t Firmware<= 5.4.2.27
NetgearGs724t Firmware<= 6.3.1.16
NetgearGs728tpsb Firmware<= 5.3.0.29
NetgearGs728tsb Firmware<= 5.3.0.29
NetgearGs728txs Firmware<= 6.1.0.35
NetgearGs748t Firmware<= 5.4.2.27
NetgearGs748t Firmware<= 6.3.1.16
NetgearGs752tpsb Firmware<= 5.3.0.29
NetgearGs752tsb Firmware<= 5.3.0.29
NetgearGs752txs Firmware<= 6.1.0.35
NetgearM4200 Firmware<= 12.0.2.10
NetgearM4300 Firmware<= 12.0.2.10
NetgearM5300 Firmware<= 11.0.0.28
NetgearM6100 Firmware<= 11.0.0.28
NetgearM7100 Firmware<= 11.0.0.28
NetgearS3300 Firmware<= 6.6.1.4
NetgearXs708t Firmware<= 6.6.0.11
NetgearXs712t Firmware<= 6.1.0.34
NetgearXs716t Firmware<= 6.6.0.11

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-18860?
Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and earlier, GS716Tv3 6.3.1.16 and earlier, GS724Tv3 5.4.2.27 and earlier, GS724Tv4 6.3.1.16 and earlier, GS728TPSB 5.3.0.29 and earlier, GS728TSB 5.3.0.29 and earlier, GS728TXS 6.1.0.35 and earlier, GS748Tv4 5.4.2.27 and earlier, GS748Tv5 6.3.1.16 and earlier, GS752TPSB 5.3.0.29 and earlier, GS752TSB 5.3.0.29 and earlier, GS752TXS 6.1.0.35 and earlier, M4200 12.0.2.10 and earlier, M4300 12.0.2.10 and earlier, M5300 11.0.0.28 and earlier, M6100 11.0.0.28 and earlier, M7100 11.0.0.28 and earlier, S3300 6.6.1.4 and earlier, XS708T 6.6.0.11 and earlier, XS712T 6.1.0.34 and earlier, and XS716T 6.6.0.11 and earlier.
How severe is CVE-2017-18860?
CVE-2017-18860 has a CVSS score of 7.7/10 (HIGH severity). The EPSS model estimates a 0.52% probability of exploitation in the next 30 days.
How do I fix CVE-2017-18860?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-18860?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST