← Vulnerability feed

Vulnerability record · CVE-2017-18786 · published 22 April 2020

CVE-2017-18786: Netgear d6200 firmware injection vulnerability

Netgear · D6200 Firmware

Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.

7.8 CVSS 3.1 High EPSS 0.74% · top 46.9% CWE-74 · Injection
7.8CVSS 3.1 base score, v2 4.6
0.74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18786 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-35799Netgear d3600 firmware out-of-bounds write vulnerabilityCertain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 befor…EPSS 1.2%9.8CVE-2020-26927Netgear ac2100 firmware vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R60…EPSS 1.1%9.8CVE-2020-26908Netgear d6200 firmware vulnerabilityCertain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6…EPSS 2.1%9.8CVE-2019-20730Netgear d3600 firmware sql injection vulnerabilityCertain NETGEAR devices are affected by SQL injection. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6200 before 1.1.00.28, D6220 befor…EPSS 0.91%9.8CVE-2016-11014Netgear jnr1010 firmware insufficient session expiration vulnerabilityNETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.EPSS 2.5%8.8CVE-2021-45641Netgear d3600 firmware vulnerabilityCertain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D620…EPSS 0.69%8.8CVE-2021-45551Netgear d6200 firmware command injection vulnerabilityCertain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020…EPSS 1.5%8.8CVE-2020-26912Netgear d6200 firmware cross-site request forgery vulnerabilityCertain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2017-18786), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.