Vulnerability record · CVE-2017-6862 · published 26 May 2017
CVE-2017-6862: NETGEAR WNR2000 routers authentication bypass and buffer overflow RCE
Netgear · Wnr2000 Firmware
NETGEAR WNR2000v3, v4 and v5 routers before their fixed firmware versions contain a buffer overflow in a parameter handled by the administration webapp, which also allows authentication bypass. Because the flaw is reachable over the network without credentials, it exposes affected routers to remote code execution and full device compromise.
Description
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with CVSS 9.8 and confirmed exploitation in CISA KEV.
What it is
NETGEAR WNR2000v3, v4 and v5 routers before their fixed firmware versions contain a buffer overflow in a parameter handled by the administration webapp, which also allows authentication bypass. Because the flaw is reachable over the network without credentials, it exposes affected routers to remote code execution and full device compromise.
Impact
An unauthenticated attacker can bypass authentication and execute arbitrary code on the router, gaining full control of the device and its network position.
Attack surface
The flaw is reached remotely through the administration webapp over the network, per the CVSS vector AV:N/PR:N/UI:N, so no authentication or user interaction is required.
Exploitation
CVE-2017-6862 is listed in CISA KEV (added 2022-06-08), indicating known exploitation, and EPSS gives a 30-day probability of roughly 0.43 (98.6th percentile); no ransomware campaign use is documented.
What to do
- Update WNR2000v3 to 1.1.2.14 or later, WNR2000v4 to 1.0.0.66 or later, and WNR2000v5 to 1.0.0.42 or later per the NETGEAR advisory.
- If the device cannot be patched, replace it or remove it from production use.
- Disable remote administration and restrict the admin web interface to trusted internal networks only.
- Segment or isolate the router so a compromise cannot reach other internal systems.
Detection
- Monitor router and perimeter logs for unexpected requests to the administration webapp, especially malformed or oversized parameters.
- Alert on unexpected outbound connections or configuration changes originating from the router.
- Check firmware versions of deployed WNR2000v3/v4/v5 devices against the fixed versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6862 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "NETGEAR Multiple Devices Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98740 | Broken LinkThird Party AdvisoryVDB Entry |
| https://kb.netgear.com/000038542/Security-Advisory-for-Unauthenticated-Remote-Code-Execution-on-Some-Routers-PSV-2016-02 | Vendor Advisory |
| https://www.on-x.com/sites/default/files/on-x_-_security_advisory_-_netgear_wnr2000v5_-_cve-2017-6862.pdf | Broken Link |
| http://www.securityfocus.com/bid/98740 | Broken LinkThird Party AdvisoryVDB Entry |
| https://kb.netgear.com/000038542/Security-Advisory-for-Unauthenticated-Remote-Code-Execution-on-Some-Routers-PSV-2016-02 | Vendor Advisory |
| https://www.on-x.com/sites/default/files/on-x_-_security_advisory_-_netgear_wnr2000v5_-_cve-2017-6862.pdf | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6862 | US Government Resource |
Track CVE-2017-6862 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6862), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.