VYPR

Nighthawk M1

by Netgear

CVEs (4)

  • CVE-2019-14527CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.

  • CVE-2021-27253HigApr 14, 2021
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2019-14526HigAug 14, 2019
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web…

  • CVE-2026-11739MedAug 11, 2026
    risk 0.32cvss epss 0.01

    A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.