VYPR

NMS300

by Netgear

CVEs (16)

  • CVE-2016-1524CriFeb 13, 2016
    risk 0.73cvss 9.6epss 0.94

    Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via…

  • CVE-2023-49693CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

  • CVE-2021-27274CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.08

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class.…

  • CVE-2020-35797CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.

  • CVE-2021-27273HigMar 29, 2021
    risk 0.62cvss 8.8epss 0.65

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2023-44450HigMay 3, 2024
    risk 0.61cvss 8.8epss 0.54

    NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is…

  • CVE-2023-44449HigMay 3, 2024
    risk 0.61cvss 8.8epss 0.53

    NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to…

  • CVE-2021-27275HigMar 29, 2021
    risk 0.60cvss 8.3epss 0.73

    This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication…

  • CVE-2024-5247HigMay 23, 2024
    risk 0.59cvss 8.8epss 0.27

    NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is…

  • CVE-2020-35789HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.03

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

  • CVE-2020-35781HigDec 30, 2020
    risk 0.54cvss 8.3epss 0.01

    NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.

  • CVE-2021-27276HigMar 29, 2021
    risk 0.52cvss 7.1epss 0.72

    This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2021-27272HigMar 29, 2021
    risk 0.52cvss 7.1epss 0.74

    This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2024-5245HigMay 23, 2024
    risk 0.51cvss 7.8epss 0.01

    NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. An attacker must first obtain the…

  • CVE-2020-35779HigDec 30, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.

  • CVE-2020-35780HigDec 30, 2020
    risk 0.46cvss 7.1epss 0.01

    NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.