XR1000
by Netgear
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-45654 | Cri | 0.62 | 9.6 | 0.01 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information. | ||
| CVE-2021-45514 | Cri | 0.62 | 9.6 | 0.01 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker. | ||
| CVE-2021-45513 | Cri | 0.62 | 9.6 | 0.01 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker. | ||
| CVE-2024-35517 | Hig | 0.56 | 8.4 | 0.15 | Oct 11, 2024 | Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter. | ||
| CVE-2025-25246 | Hig | 0.53 | 8.1 | 0.01 | Feb 5, 2025 | NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users. | ||
| CVE-2021-45643 | Hig | 0.53 | 8.2 | 0.00 | Dec 26, 2021 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, and XR1000 before 1.0.0.58. | ||
| CVE-2021-45510 | Hig | 0.53 | 8.2 | 0.01 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass. | ||
| CVE-2021-34870 | Med | 0.42 | 6.5 | 0.01 | Jan 25, 2022 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP… | ||
| CVE-2021-45519 | Med | 0.42 | 6.5 | 0.00 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service. | ||
| CVE-2021-45518 | Med | 0.42 | 6.5 | 0.00 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service. | ||
| CVE-2021-45517 | Med | 0.42 | 6.5 | 0.00 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service. | ||
| CVE-2021-45522 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password. |
- risk 0.62cvss 9.6epss 0.01
NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information.
- risk 0.62cvss 9.6epss 0.01
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
- risk 0.62cvss 9.6epss 0.01
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
- risk 0.56cvss 8.4epss 0.15
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
- risk 0.53cvss 8.1epss 0.01
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
- risk 0.53cvss 8.2epss 0.00
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, and XR1000 before 1.0.0.58.
- risk 0.53cvss 8.2epss 0.01
NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass.
- risk 0.42cvss 6.5epss 0.01
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP…
- risk 0.42cvss 6.5epss 0.00
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
- risk 0.42cvss 6.5epss 0.00
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
- risk 0.42cvss 6.5epss 0.00
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
- risk 0.40cvss 6.1epss 0.01
NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.