← Vulnerability feed

Vulnerability record · CVE-2017-18834 · published 20 April 2020

CVE-2017-18834: Netgear m4300-28g firmware cross-site scripting vulnerability

Netgear · M4300 28g Firmware

Certain NETGEAR devices are affected by reflected XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.

6.1 CVSS 3.1 Medium EPSS 0.51% · top 58.7% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Certain NETGEAR devices are affected by reflected XSS. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before 12.0.2.15, M4300-24X before 12.0.2.15, M4300-48X before 12.0.2.15, and M4200 before 12.0.2.15.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18834 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-18858Netgear m4200-10mg-poe\+ firmware os command injection vulnerabilityCertain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300…EPSS 3.1%7.8CVE-2017-18837Netgear m4300-28g firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…EPSS 0.31%7.8CVE-2017-18830Netgear m4300-28g firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…EPSS 0.31%7.8CVE-2017-18829Netgear m4300-28g firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…EPSS 0.27%7.8CVE-2017-18826Netgear m4300-28g firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…EPSS 0.31%7.8CVE-2017-18822Netgear m4300-28g firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…EPSS 0.37%7.8CVE-2017-18838Netgear m4300-28g firmware improper privilege management vulnerabilityCertain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ bef…EPSS 0.27%7.7CVE-2017-18860Netgear fs752tp firmware injection vulnerabilityCertain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110T…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2017-18834), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.