CVE-2026-15757 (GCVE-0-2026-15757)
Vulnerability from cvelistv5
Published
2026-07-14 17:46
Modified
2026-07-15 16:50
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-20 - Improper input validation
Summary
A security flaw was discovered in the NETGEAR DGND3700v1 that could
allow someone on the same local WiFi network to send unauthorized commands to
the device.
This issue was identified through testing in a controlled research
environment using a simulated version of the router's software and has not been
confirmed on physical production devices.
References
| URL | Tags | |||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| NETGEAR | DGND3700v1 |
Version: 0 < |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15757",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-15T14:02:42.091535Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T14:02:51.002Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "DGND3700v1",
"vendor": "NETGEAR",
"versions": [
{
"lessThanOrEqual": "V1.0.0.17",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Security Research Center (SRC) @ Concordia University"
}
],
"datePublic": "2026-07-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eA security flaw was discovered in the NETGEAR DGND3700v1 that could\nallow someone on the same local WiFi network to send unauthorized commands to\nthe device.\u003c/p\u003e\u003cp\u003e\u003cspan\u003eThis issue was identified through testing in a controlled research\nenvironment using a simulated version of the router\u0027s software and has not been\nconfirmed on physical production devices.\u003c/span\u003e\u003c/p\u003e"
}
],
"value": "A security flaw was discovered in the NETGEAR DGND3700v1 that could\nallow someone on the same local WiFi network to send unauthorized commands to\nthe device.\n\n\n\nThis issue was identified through testing in a controlled research\nenvironment using a simulated version of the router\u0027s software and has not been\nconfirmed on physical production devices."
}
],
"impacts": [
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
},
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "ADJACENT",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "UNREPORTED",
"privilegesRequired": "NONE",
"providerUrgency": "AMBER",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "DIFFUSE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "LOW"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper input validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-15T16:50:16.246Z",
"orgId": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"shortName": "NETGEAR"
},
"references": [
{
"tags": [
"patch",
"product"
],
"url": "https://www.netgear.com/support/product/dgnd3700v1"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eNETGEAR\u0026nbsp;DGND3700v1\u0026nbsp;has reached End-of-Support phase, and no further security\n updates are planned. NETGEAR\u0026nbsp;strongly recommends replacing these \ndevices with newer NETGEAR models to ensure continued security support \nand updates.\u003c/p\u003e"
}
],
"value": "NETGEAR\u00a0DGND3700v1\u00a0has reached End-of-Support phase, and no further security\n updates are planned. NETGEAR\u00a0strongly recommends replacing these \ndevices with newer NETGEAR models to ensure continued security support \nand updates."
}
],
"source": {
"discovery": "EXTERNAL"
},
"tags": [
"unsupported-when-assigned"
],
"title": "Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "a2826606-91e7-4eb6-899e-8484bd4575d5",
"assignerShortName": "NETGEAR",
"cveId": "CVE-2026-15757",
"datePublished": "2026-07-14T17:46:15.979Z",
"dateReserved": "2026-07-14T16:28:54.296Z",
"dateUpdated": "2026-07-15T16:50:16.246Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-15757\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-07-15T14:02:42.091535Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-07-15T14:02:47.515Z\"}}], \"cna\": {\"tags\": [\"unsupported-when-assigned\"], \"title\": \"Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router\", \"source\": {\"discovery\": \"EXTERNAL\"}, \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"Security Research Center (SRC) @ Concordia University\"}], \"impacts\": [{\"capecId\": \"CAPEC-248\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-248 Command Injection\"}]}, {\"capecId\": \"CAPEC-100\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-100 Overflow Buffers\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV4_0\": {\"Safety\": \"NOT_DEFINED\", \"version\": \"4.0\", \"Recovery\": \"NOT_DEFINED\", \"baseScore\": 6.3, \"Automatable\": \"NOT_DEFINED\", \"attackVector\": \"ADJACENT\", \"baseSeverity\": \"MEDIUM\", \"valueDensity\": \"DIFFUSE\", \"vectorString\": \"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber\", \"exploitMaturity\": \"UNREPORTED\", \"providerUrgency\": \"AMBER\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"attackRequirements\": \"NONE\", \"privilegesRequired\": \"NONE\", \"subIntegrityImpact\": \"NONE\", \"vulnIntegrityImpact\": \"HIGH\", \"subAvailabilityImpact\": \"NONE\", \"vulnAvailabilityImpact\": \"HIGH\", \"subConfidentialityImpact\": \"NONE\", \"vulnConfidentialityImpact\": \"HIGH\", \"vulnerabilityResponseEffort\": \"LOW\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"vendor\": \"NETGEAR\", \"product\": \"DGND3700v1\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"versionType\": \"custom\", \"lessThanOrEqual\": \"V1.0.0.17\"}], \"defaultStatus\": \"unaffected\"}], \"solutions\": [{\"lang\": \"en\", \"value\": \"NETGEAR\\u00a0DGND3700v1\\u00a0has reached End-of-Support phase, and no further security\\n updates are planned. NETGEAR\\u00a0strongly recommends replacing these \\ndevices with newer NETGEAR models to ensure continued security support \\nand updates.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eNETGEAR\u0026nbsp;DGND3700v1\u0026nbsp;has reached End-of-Support phase, and no further security\\n updates are planned. NETGEAR\u0026nbsp;strongly recommends replacing these \\ndevices with newer NETGEAR models to ensure continued security support \\nand updates.\u003c/p\u003e\", \"base64\": false}]}], \"datePublic\": \"2026-07-14T00:00:00.000Z\", \"references\": [{\"url\": \"https://www.netgear.com/support/product/dgnd3700v1\", \"tags\": [\"patch\", \"product\"]}, {\"url\": \"https://kb.netgear.com/000070859/July-2026-NETGEAR-Security-Advisory\", \"tags\": [\"vendor-advisory\"]}], \"x_generator\": {\"engine\": \"Vulnogram 1.0.3\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"A security flaw was discovered in the NETGEAR DGND3700v1 that could\\nallow someone on the same local WiFi network to send unauthorized commands to\\nthe device.\\n\\n\\n\\nThis issue was identified through testing in a controlled research\\nenvironment using a simulated version of the router\u0027s software and has not been\\nconfirmed on physical production devices.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"\u003cp\u003eA security flaw was discovered in the NETGEAR DGND3700v1 that could\\nallow someone on the same local WiFi network to send unauthorized commands to\\nthe device.\u003c/p\u003e\u003cp\u003e\u003cspan\u003eThis issue was identified through testing in a controlled research\\nenvironment using a simulated version of the router\u0027s software and has not been\\nconfirmed on physical production devices.\u003c/span\u003e\u003c/p\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-20\", \"description\": \"CWE-20 Improper input validation\"}]}], \"providerMetadata\": {\"orgId\": \"a2826606-91e7-4eb6-899e-8484bd4575d5\", \"shortName\": \"NETGEAR\", \"dateUpdated\": \"2026-07-15T16:50:16.246Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-15757\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-07-15T16:50:16.246Z\", \"dateReserved\": \"2026-07-14T16:28:54.296Z\", \"assignerOrgId\": \"a2826606-91e7-4eb6-899e-8484bd4575d5\", \"datePublished\": \"2026-07-14T17:46:15.979Z\", \"assignerShortName\": \"NETGEAR\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…