CVE-2026-15757 (GCVE-0-2026-15757)
Vulnerability from cvelistv5
Published
2026-07-14 17:46
Modified
2026-07-15 16:50
CWE
  • CWE-20 - Improper input validation
Summary
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on physical production devices.
Impacted products
Vendor Product Version
NETGEAR DGND3700v1 Version: 0   <
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-15757",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-15T14:02:42.091535Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-15T14:02:51.002Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "DGND3700v1",
          "vendor": "NETGEAR",
          "versions": [
            {
              "lessThanOrEqual": "V1.0.0.17",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Security Research Center (SRC) @ Concordia University"
        }
      ],
      "datePublic": "2026-07-14T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eA security flaw was discovered in the NETGEAR DGND3700v1 that could\nallow someone on the same local WiFi network to send unauthorized commands to\nthe device.\u003c/p\u003e\u003cp\u003e\u003cspan\u003eThis issue was identified through testing in a controlled research\nenvironment using a simulated version of the router\u0027s software and has not been\nconfirmed on physical production devices.\u003c/span\u003e\u003c/p\u003e"
            }
          ],
          "value": "A security flaw was discovered in the NETGEAR DGND3700v1 that could\nallow someone on the same local WiFi network to send unauthorized commands to\nthe device.\n\n\n\nThis issue was identified through testing in a controlled research\nenvironment using a simulated version of the router\u0027s software and has not been\nconfirmed on physical production devices."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-248",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-248 Command Injection"
            }
          ]
        },
        {
          "capecId": "CAPEC-100",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-100 Overflow Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "ADJACENT",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "UNREPORTED",
            "privilegesRequired": "NONE",
            "providerUrgency": "AMBER",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "DIFFUSE",
            "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "LOW"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-20",
              "description": "CWE-20 Improper input validation",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-15T16:50:16.246Z",
        "orgId": "a2826606-91e7-4eb6-899e-8484bd4575d5",
        "shortName": "NETGEAR"
      },
      "references": [
        {
          "tags": [
            "patch",
            "product"
          ],
          "url": "https://www.netgear.com/support/product/dgnd3700v1"
        },
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eNETGEAR\u0026nbsp;DGND3700v1\u0026nbsp;has reached End-of-Support phase, and no further security\n updates are planned. NETGEAR\u0026nbsp;strongly recommends replacing these \ndevices with newer NETGEAR models to ensure continued security support \nand updates.\u003c/p\u003e"
            }
          ],
          "value": "NETGEAR\u00a0DGND3700v1\u00a0has reached End-of-Support phase, and no further security\n updates are planned. NETGEAR\u00a0strongly recommends replacing these \ndevices with newer NETGEAR models to ensure continued security support \nand updates."
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "tags": [
        "unsupported-when-assigned"
      ],
      "title": "Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router",
      "x_generator": {
        "engine": "Vulnogram 1.0.3"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a2826606-91e7-4eb6-899e-8484bd4575d5",
    "assignerShortName": "NETGEAR",
    "cveId": "CVE-2026-15757",
    "datePublished": "2026-07-14T17:46:15.979Z",
    "dateReserved": "2026-07-14T16:28:54.296Z",
    "dateUpdated": "2026-07-15T16:50:16.246Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-15757\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-15T14:02:42.091535Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-15T14:02:47.515Z\"}}], \"cna\": {\"tags\": [\"unsupported-when-assigned\"], \"title\": \"Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router\", \"source\": {\"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Security Research Center (SRC) @ Concordia University\"}], \"impacts\": [{\"capecId\": \"CAPEC-248\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-248 Command Injection\"}]}, {\"capecId\": \"CAPEC-100\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-100 Overflow Buffers\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 6.3, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"ADJACENT\", \"baseSeverity\": \"MEDIUM\", \"valueDensity\": \"DIFFUSE\", \"vectorString\": \"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber\", \"exploitMaturity\": \"UNREPORTED\", \"providerUrgency\": \"AMBER\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"attackRequirements\": \"NONE\", \"privilegesRequired\": \"NONE\", \"subIntegrityImpact\": \"NONE\", \"vulnIntegrityImpact\": \"HIGH\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"HIGH\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"HIGH\", \"vulnerabilityResponseEffort\": \"LOW\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"NETGEAR\", \"product\": \"DGND3700v1\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"V1.0.0.17\"}], \"defaultStatus\": \"unaffected\"}], \"solutions\": [{\"lang\": \"en\", \"value\": \"NETGEAR\\u00a0DGND3700v1\\u00a0has reached End-of-Support phase, and no further security\\n updates are planned. NETGEAR\\u00a0strongly recommends replacing these \\ndevices with newer NETGEAR models to ensure continued security support \\nand updates.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eNETGEAR\u0026nbsp;DGND3700v1\u0026nbsp;has reached End-of-Support phase, and no further security\\n updates are planned. NETGEAR\u0026nbsp;strongly recommends replacing these \\ndevices with newer NETGEAR models to ensure continued security support \\nand updates.\u003c/p\u003e\", \"base64\": false}]}], \"datePublic\": \"2026-07-14T00:00:00.000Z\", \"references\": [{\"url\": \"https://www.netgear.com/support/product/dgnd3700v1\", \"tags\": [\"patch\", \"product\"]}, {\"url\": \"https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory\", \"tags\": [\"vendor-advisory\"]}], \"x_generator\": {\"engine\": \"Vulnogram 1.0.3\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"A security flaw was discovered in the NETGEAR DGND3700v1 that could\\nallow someone on the same local WiFi network to send unauthorized commands to\\nthe device.\\n\\n\\n\\nThis issue was identified through testing in a controlled research\\nenvironment using a simulated version of the router\u0027s software and has not been\\nconfirmed on physical production devices.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eA security flaw was discovered in the NETGEAR DGND3700v1 that could\\nallow someone on the same local WiFi network to send unauthorized commands to\\nthe device.\u003c/p\u003e\u003cp\u003e\u003cspan\u003eThis issue was identified through testing in a controlled research\\nenvironment using a simulated version of the router\u0027s software and has not been\\nconfirmed on physical production devices.\u003c/span\u003e\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-20\", \"description\": \"CWE-20 Improper input validation\"}]}], \"providerMetadata\": {\"orgId\": \"a2826606-91e7-4eb6-899e-8484bd4575d5\", \"shortName\": \"NETGEAR\", \"dateUpdated\": \"2026-07-15T16:50:16.246Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-15757\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-15T16:50:16.246Z\", \"dateReserved\": \"2026-07-14T16:28:54.296Z\", \"assignerOrgId\": \"a2826606-91e7-4eb6-899e-8484bd4575d5\", \"datePublished\": \"2026-07-14T17:46:15.979Z\", \"assignerShortName\": \"NETGEAR\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…