Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-18860


Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and earlier, GS716Tv3 6.3.1.16 and earlier, GS724Tv3 5.4.2.27 and earlier, GS724Tv4 6.3.1.16 and earlier, GS728TPSB 5.3.0.29 and earlier, GS728TSB 5.3.0.29 and earlier, GS728TXS 6.1.0.35 and earlier, GS748Tv4 5.4.2.27 and earlier, GS748Tv5 6.3.1.16 and earlier, GS752TPSB 5.3.0.29 and earlier, GS752TSB 5.3.0.29 and earlier, GS752TXS 6.1.0.35 and earlier, M4200 12.0.2.10 and earlier, M4300 12.0.2.10 and earlier, M5300 11.0.0.28 and earlier, M6100 11.0.0.28 and earlier, M7100 11.0.0.28 and earlier, S3300 6.6.1.4 and earlier, XS708T 6.6.0.11 and earlier, XS712T 6.1.0.34 and earlier, and XS716T 6.6.0.11 and earlier.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.7, requiring local system access to exploit with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 50 products from netgear, from netgear, from netgear and 47 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2020, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2020-04-29T14:15:14.013

Last Modified

2024-11-21T03:21:06.917

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.7 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear fs752tp_firmware ≤ 5.4.2.19 Yes
Hardware netgear fs752tp - No
Operating System netgear gs108t_firmware ≤ 5.4.2.29 Yes
Hardware netgear gs108tv2 - No
Operating System netgear gs110tp_firmware ≤ 5.4.2.29 Yes
Hardware netgear gs110tp - No
Operating System netgear gs418tpp_firmware ≤ 6.6.2.6 Yes
Hardware netgear gs418tpp - No
Operating System netgear gs510tlp_firmware ≤ 6.6.2.6 Yes
Hardware netgear gs510tlp - No
Operating System netgear gs510tp_firmware ≤ 5.04.2.27 Yes
Hardware netgear gs510tp - No
Operating System netgear gs510tpp_firmware ≤ 6.6.2.6 Yes
Hardware netgear gs510tpp - No
Operating System netgear gs716t_firmware ≤ 5.4.2.27 Yes
Hardware netgear gs716t v2 No
Operating System netgear gs716t_firmware ≤ 6.3.1.16 Yes
Hardware netgear gs716t v3 No
Operating System netgear gs724t_firmware ≤ 5.4.2.27 Yes
Hardware netgear gs724t v3 No
Operating System netgear gs724t_firmware ≤ 6.3.1.16 Yes
Hardware netgear gs724t v4 No
Operating System netgear gs728tpsb_firmware ≤ 5.3.0.29 Yes
Hardware netgear gs728tpsb - No
Operating System netgear gs728tsb_firmware ≤ 5.3.0.29 Yes
Hardware netgear gs728tsb - No
Operating System netgear gs728txs_firmware ≤ 6.1.0.35 Yes
Hardware netgear gs728txs - No
Operating System netgear gs748t_firmware ≤ 5.4.2.27 Yes
Hardware netgear gs748t v4 No
Operating System netgear gs748t_firmware ≤ 6.3.1.16 Yes
Hardware netgear gs748t v5 No
Operating System netgear gs752tpsb_firmware ≤ 5.3.0.29 Yes
Hardware netgear gs752tpsb - No
Operating System netgear gs752tsb_firmware ≤ 5.3.0.29 Yes
Hardware netgear gs752tsb - No
Operating System netgear gs752txs_firmware ≤ 6.1.0.35 Yes
Hardware netgear gs752txs - No
Operating System netgear m4200_firmware ≤ 12.0.2.10 Yes
Hardware netgear m4200 - No
Operating System netgear m4300_firmware ≤ 12.0.2.10 Yes
Hardware netgear m4300 - No
Operating System netgear m5300_firmware ≤ 11.0.0.28 Yes
Hardware netgear m5300 - No
Operating System netgear m6100_firmware ≤ 11.0.0.28 Yes
Hardware netgear m6100 - No
Operating System netgear m7100_firmware ≤ 11.0.0.28 Yes
Hardware netgear m7100 - No
Operating System netgear s3300_firmware ≤ 6.6.1.4 Yes
Hardware netgear s3300 - No
Operating System netgear xs708t_firmware ≤ 6.6.0.11 Yes
Hardware netgear xs708t - No
Operating System netgear xs712t_firmware ≤ 6.1.0.34 Yes
Hardware netgear xs712t - No
Operating System netgear xs716t_firmware ≤ 6.6.0.11 Yes
Hardware netgear xs716t - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For netgear's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.