LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6862: NETGEAR Multiple Devices Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 22, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6862 to its Known Exploited Vulnerabilities catalog on Jun 8, 2022, with a federal patch deadline of Jun 22, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

CVE-2017-6862 is a buffer overflow vulnerability affecting multiple NETGEAR devices. According to CISA, it allows authentication bypass and remote code execution. For IT and security teams, this matters because compromised network devices can give an attacker a foothold on the perimeter or inside the LAN, from which they may pivot, intercept traffic, or maintain persistence. Confirm exact product coverage and fixed releases against the vendor advisory.

The weakness is tracked as CWE-119 (improper restriction of operations within the bounds of a memory buffer). Successful abuse can let an unauthenticated or lightly authenticated remote party take control of the device. Treat any internet-facing or poorly segmented NETGEAR appliance in scope until you verify otherwise.

How it works

CWE-119 covers flaws where software writes or copies data past the end of an allocated buffer. On embedded network gear this often appears in parsing of management protocols, web interfaces, or other network-facing services. An attacker who can reach the vulnerable service crafts input that overflows a buffer, corrupting adjacent memory. Depending on the layout and protections present on the device, that corruption can be leveraged to bypass authentication checks and achieve remote code execution on the device itself.

Public detail in the provided record does not describe the exact protocol, packet format, or memory layout. Do not assume a particular exploit path; treat any reachable management or service interface on affected models as potentially abusable until the vendor advisory and your own testing say otherwise. The practical outcome is full or near-full control of the appliance, which can then be used to alter configuration, capture credentials, or forward traffic.

Am I affected? How to find it in your systems

NETGEAR devices commonly appear as consumer and small-business routers, gateways, access points, and related network appliances. Inventory every NETGEAR unit on your networks, including those used at branch sites, labs, and home-office connections that reach corporate resources.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed firmware only from NETGEAR’s official support channels, verify integrity if the vendor provides checksums or signatures, and schedule installation according to your change process. After upgrade, re-check the running version and confirm the advisory’s remediation notes are satisfied.

If you can't patch immediately

Reduce attack surface until you can apply the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to broader compromise and data exposure, even when ransomware use is not documented for this CVE. If you have indicators of compromise or the device handled sensitive traffic, follow your incident-response process: isolate, preserve logs and firmware images, rotate credentials that traversed the device, and assess downstream systems. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNETGEAR · Multiple Devices
WeaknessCWE-119
Added to CISA KEVJun 8, 2022
Federal patch deadlineJun 22, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities