CVE-2017-18852: NETGEAR r7300dst Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Certain NETGEAR devices are affected by CSRF and authentication bypass. This affects R7300DST before 1.0.0.54, R8300 before 1.0.2.100_1.0.82, R8500 before 1.0.2.100_1.0.82, and WNDR3400v3 before 1.0.1.14.

Affected products

  • NETGEAR r7300dst Firmware: before 1.0.0.54 (fixed in 1.0.0.54)
  • NETGEAR r8300 Firmware: before 1.0.2.100_1.0.82 (fixed in 1.0.2.100_1.0.82)
  • NETGEAR r8500 Firmware: before 1.0.2.100_1.0.82 (fixed in 1.0.2.100_1.0.82)
  • NETGEAR WNDR3400 Firmware: before 1.0.1.14 (fixed in 1.0.1.14)

Published 2020-04-20. Last modified 2026-06-17.