Description
A security flaw was discovered in the NETGEAR DGND3700v1 that could
allow someone on the same local WiFi network to send unauthorized commands to
the device.



This issue was identified through testing in a controlled research
environment using a simulated version of the router's software and has not been
confirmed on physical production devices.
Published: 2026-07-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local Wi‑Fi network user can send unauthorized commands to the NETGEAR DGND3700v1 router due to insufficient input validation. The flaw enables a threat actor to issue device control commands, potentially compromising confidentiality or availability of the network. The vulnerability is classified as CWE‑20 and carries a CVSS score of 6.3, indicating a moderate severity. The EPSS score is below 1%, implying a very low exploitation probability at the time of analysis. The issue was identified in a simulated environment and has not been confirmed on physical production devices. The attack vector is inferred to be local wireless access, requiring the attacker to be connected to the same Wi‑Fi network.

Affected Systems

The affected product is NETGEAR’s DGND3700v1 modem router. No specific version ranges are listed beyond the model name, and the device has reached its End‑of‑Support phase, meaning no further security updates are planned.

Risk and Exploitability

The CVSS score of 6.3 classifies the weakness as moderate severity. The EPSS indicates a very low probability of exploitation (<1%). Attackers already connected to the local Wi‑Fi network could send crafted requests that bypass input validation and invoke arbitrary commands on the router. Because the device has reached End‑of‑Support and no patch is available, the risk remains until the device is replaced.

Generated by OpenCVE AI on July 31, 2026 at 05:55 UTC.

Remediation

Vendor Solution

NETGEAR DGND3700v1 has reached End-of-Support phase, and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates.


OpenCVE Recommended Actions

  • Replace the DGND3700v1 with a newer NETGEAR model that receives ongoing security updates
  • Disable remote administration, WPS, UPnP, and other unnecessary services to limit the attack surface
  • Restrict access to the router’s management interface to known static IPs or VLANs, preventing unauthorized local requests

Generated by OpenCVE AI on July 31, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
References

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on physical production devices.
Title Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-07-15T16:50:16.246Z

Reserved: 2026-07-14T16:28:54.296Z

Link: CVE-2026-15757

cve-icon Vulnrichment

Updated: 2026-07-15T14:02:47.515Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation