CVE-2018-11106: NETGEAR WC7500 Firmware

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.

Affected products

  • NETGEAR WC7500 Firmware: before 6.5.3.5 (fixed in 6.5.3.5)
  • NETGEAR WC7520 Firmware: before 2.5.0.46 (fixed in 2.5.0.46)
  • NETGEAR WC7600V1 Firmware: before 6.5.3.5 (fixed in 6.5.3.5)
  • NETGEAR WC7600V2 Firmware: before 6.5.3.5 (fixed in 6.5.3.5)
  • NETGEAR WC9500 Firmware: before 6.5.3.5 (fixed in 6.5.3.5)

Published 2020-04-01. Last modified 2026-06-17.