CVE Feed

    Dashboard / CVE / CVE-2018-11106

    CVE-2018-11106

    NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.

    Published:Apr 1, 2020
    Last Modified:Nov 21, 2024
    EPS:Apr 1, 2020
    EPSS Score:0.02046
    CVSS Score:9.8

    Affected Products

    Vendor
    Netgear
    Product
    Wc7500
    Vendor
    Netgear
    Product
    Wc7500 Firmware
    Vendor
    Netgear
    Product
    Wc7520
    Vendor
    Netgear
    Product
    Wc7520 Firmware
    Vendor
    Netgear
    Product
    Wc7600v1
    Vendor
    Netgear
    Product
    Wc7600v1 Firmware
    Vendor
    Netgear
    Product
    Wc7600v2
    Vendor
    Netgear
    Product
    Wc7600v2 Firmware
    Vendor
    Netgear
    Product
    Wc9500
    Vendor
    Netgear
    Product
    Wc9500 Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High