Netgear Security Advisory for Pre-Authentication Command Injection [CVE-2018-11106]
CVE Number = CVE-2018-11106 ( PSV-2018-0051)
NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models:
- WC7500, running firmware versions prior to 6.5.3.5
- WC7520, running firmware versions prior to 2.5.0.46
- WC7600v1, running firmware versions prior to 6.5.3.5
- WC7600v2, running firmware versions prior to 6.5.3.5
- WC9500, running firmware versions prior to 6.5.3.5
NETGEAR strongly recommends that you download the latest firmware as soon as possible.
To download the latest firmware for your NETGEAR product:
- Visit NETGEAR Support.
- Start typing your model number in the search box, then select your model from the drop-down menu as soon as it appears.
If you do not see a drop-down menu, make sure that you entered your model number correctly, or select a product category to browse for your product model. - Click Downloads.
- Under Current Versions, select the download whose title begins with Firmware Version.
- Click Download.
- Follow the instructions in your product’s user manual, firmware release notes, or product support page to install the new firmware.
The pre-authentication command injection in request_handler.php vulnerability remains if you do not complete all recommended steps. NETGEAR is not responsible for any consequences that could have been avoided by following the recommendations in this notification.
![Netgear Security Advisory for Pre-Authentication Command Injection [CVE-2018-11106]](https://i0.wp.com/www.systemtek.co.uk/wp-content/uploads/2022/01/blank-profile-hi.png?resize=100%2C100)
Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.