Impact
A local Wi‑Fi network user can send unauthorized commands to the NETGEAR DGND3700v1 router due to insufficient input validation. The flaw enables a threat actor to issue device control commands, potentially compromising confidentiality or availability of the network. The vulnerability is classified as CWE‑20 and carries a CVSS score of 6.3, indicating a moderate severity. The EPSS score is below 1%, implying a very low exploitation probability at the time of analysis. The issue was identified in a simulated environment and has not been confirmed on physical production devices. The attack vector is inferred to be local wireless access, requiring the attacker to be connected to the same Wi‑Fi network.
Affected Systems
The affected product is NETGEAR’s DGND3700v1 modem router. No specific version ranges are listed beyond the model name, and the device has reached its End‑of‑Support phase, meaning no further security updates are planned.
Risk and Exploitability
The CVSS score of 6.3 classifies the weakness as moderate severity. The EPSS indicates a very low probability of exploitation (<1%). Attackers already connected to the local Wi‑Fi network could send crafted requests that bypass input validation and invoke arbitrary commands on the router. Because the device has reached End‑of‑Support and no patch is available, the risk remains until the device is replaced.
OpenCVE Enrichment