CVE-2017-18858

Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300-52G 12.0.2.11 and earlier, M4300-28G-POE+ 12.0.2.11 and earlier, M4300-52G-POE+ 12.0.2.11 and earlier, M4300-8X8F 12.0.2.11 and earlier, M4300-12X12F 12.0.2.11 and earlier, M4300-24X24F 12.0.2.11 and earlier, M4300-24X 12.0.2.11 and earlier, and M4300-48X 12.0.2.11 and earlier.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:m4200-10mg-poe\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4200-10mg-poe\+:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netgear:m4300-28g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-28g:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netgear:m4300-52g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-52g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netgear:m4300-28g-poe\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-28g-poe\+:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netgear:m4300-52g-poe\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-52g-poe\+:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netgear:m4300-8x8f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-8x8f:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netgear:m4300-12x12f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-12x12f:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netgear:m4300-24x24f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-24x24f:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netgear:m4300-24x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-24x:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netgear:m4300-48x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netgear:m4300-48x:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-04-28 17:15

Updated : 2024-02-28 17:47


NVD link : CVE-2017-18858

Mitre link : CVE-2017-18858

CVE.ORG link : CVE-2017-18858


JSON object : View

Products Affected

netgear

  • m4300-28g_firmware
  • m4300-28g-poe\+
  • m4300-28g-poe\+_firmware
  • m4300-24x24f_firmware
  • m4300-8x8f
  • m4300-52g-poe\+_firmware
  • m4300-52g
  • m4300-12x12f_firmware
  • m4200-10mg-poe\+
  • m4300-52g-poe\+
  • m4200-10mg-poe\+_firmware
  • m4300-48x_firmware
  • m4300-24x_firmware
  • m4300-48x
  • m4300-52g_firmware
  • m4300-8x8f_firmware
  • m4300-28g
  • m4300-24x24f
  • m4300-12x12f
  • m4300-24x
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')