EXPOSURES › CVE-2017-6862
CVE-2017-6862
HIGH ⌖ ON CISA KEV · EXPLOITEDNetgear devices had a buffer overflow allowing authentication bypass and remote code execution, actively exploited in the wild.
A buffer overflow vulnerability in multiple Netgear devices enabled authentication bypass and remote code execution, demonstrating a critical failure to properly validate input. DIB organizations using these devices face potential data breaches and compliance violations (CMMC DF-1, DF-2). Immediate patching and vulnerability scanning are essential.
Shame score — The vulnerability's exploitation in the wild and potential for remote code execution highlights a significant negligence in secure coding practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.