« Volver al listado

CVE-2018-11106

Estado: ModificadaCrítica (9.8)—

NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-11106",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5",
      "affectedData": [
        {
          "vendor": "NETGEAR",
          "product": "WC7500",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to 6.5.3.5"
            }
          ]
        },
        {
          "vendor": "NETGEAR",
          "product": "WC7520",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to 2.5.0.46"
            }
          ]
        },
        {
          "vendor": "NETGEAR",
          "product": "WC7600v1",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to 6.5.3.5"
            }
          ]
        },
        {
          "vendor": "NETGEAR",
          "product": "WC7600v2",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to 6.5.3.5"
            }
          ]
        },
        {
          "vendor": "NETGEAR",
          "product": "WC9500",
          "versions": [
            {
              "status": "affected",
              "version": "firmware versions prior to 6.5.3.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-01T17:15:14.737",
  "references": [
    {
      "url": "https://kb.netgear.com/000058243/Security-Advisory-for-Pre-Authentication-Command-Injection-in-request-handler-php-on-Some-Wireless-Controllers-PSV-2018-0051",
      "source": "a2826606-91e7-4eb6-899e-8484bd4575d5"
    },
    {
      "url": "https://kb.netgear.com/000058243/Security-Advisory-for-Pre-Authentication-Command-Injection-in-request-handler-php-on-Some-Wireless-Controllers-PSV-2018-0051",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5."
    },
    {
      "lang": "es",
      "value": "NETGEAR presenta correcciones publicadas para una inyección de comando previa a la autenticación en una vulnerabilidad de seguridad del archivo request_handler.php en los siguientes modelos de producto: WC7500, ejecutando versiones de firmware anteriores a 6.5.3.5; WC7520, ejecutando versiones de firmware anteriores a 2.5.0.46; WC7600v1, ejecutando versiones de firmware anteriores a 6.5.3.5; WC7600v2, ejecutando versiones de firmware anteriores a 6.5.3.5; y WC9500, ejecutando versiones de firmware anteriores a 6.5.3.5."
    }
  ],
  "lastModified": "2026-06-17T01:35:17.010",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wc7500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8184DF48-1CCE-4950-921B-8A825D8CDD71",
              "versionEndExcluding": "6.5.3.5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wc7500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EB22B065-8EC8-4DA7-984A-CCB6919AF8F3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wc7520_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86CD35ED-0A90-4932-976B-A7666B3D7C7A",
              "versionEndExcluding": "2.5.0.46"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wc7520:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A58C9FE8-4BD5-41F9-9714-2D8083A51D98"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wc7600v1_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D3D43A9-6A00-4498-BEC5-46A11604A1A6",
              "versionEndExcluding": "6.5.3.5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wc7600v1:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8EB1A3EC-1069-40FC-BDDF-C3AC93E037C5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wc7600v2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB9D9CAF-D9FC-4E42-9C80-DE53C75AD578",
              "versionEndExcluding": "6.5.3.5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wc7600v2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C8BB1F1-A12D-43CC-A6D0-9633E99D746B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:netgear:wc9500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8073AB91-0F60-4EF8-9347-EB0EA6C76A76",
              "versionEndExcluding": "6.5.3.5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:netgear:wc9500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "113D0DF6-C719-4A43-80B2-463EC4323009"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "a2826606-91e7-4eb6-899e-8484bd4575d5"
}