CVE-2017-6862: NETGEAR Multiple Devices Buffer Overflow Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-06-08. EPSS: 45.7% chance of exploitation in the next 30 days.

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

Affected products

  • NETGEAR WNR2000 Firmware: before 1.0.0.42 (fixed in 1.0.0.42); before 1.0.0.66 (fixed in 1.0.0.66); before 1.1.2.14 (fixed in 1.1.2.14)

Published 2017-05-26. Last modified 2026-06-17.