VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2016-1555CriKEVApr 21, 2017
    risk 0.87cvss 9.8epss 0.98

    (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.

  • CVE-2016-10174CriKEVJan 30, 2017
    risk 0.85cvss 9.8epss 0.83

    The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

  • CVE-2017-6077CriKEVFeb 22, 2017
    risk 0.84cvss 9.8epss 0.68

    ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

  • CVE-2020-26919CriKEVOct 9, 2020
    risk 0.80cvss 9.8epss 0.57

    NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

  • CVE-2016-6277HigKEVDec 14, 2016
    risk 0.80cvss 8.8epss 1.00

    NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly…

  • CVE-2017-6862CriKEVMay 26, 2017
    risk 0.79cvss 9.8epss 0.43

    NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

  • CVE-2017-6334HigKEVMar 6, 2017
    risk 0.78cvss 8.8epss 0.72

    dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.

  • CVE-2017-5521HigKEVJan 17, 2017
    risk 0.75cvss 8.1epss 0.89

    An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely…

  • CVE-2016-5674CriAug 31, 2016
    risk 0.74cvss 9.8epss 0.95

    __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.

  • CVE-2023-38096CriMay 3, 2024
    risk 0.73cvss 9.8epss 0.82

    NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System. Authentication is not required to…

  • CVE-2016-10176CriJan 30, 2017
    risk 0.73cvss 9.8epss 0.78

    The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL,…

  • CVE-2016-1524CriFeb 13, 2016
    risk 0.73cvss 9.6epss 0.94

    Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via…

  • CVE-2016-10175CriJan 30, 2017
    risk 0.72cvss 9.8epss 0.65

    The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows…

  • CVE-2016-5675CriAug 31, 2016
    risk 0.72cvss 9.8epss 0.71

    handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.

  • CVE-2024-12847CriJan 10, 2025
    risk 0.69cvss 9.8epss 0.30

    NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been…

  • CVE-2022-29383CriMay 13, 2022
    risk 0.68cvss 9.8epss 0.49

    NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

  • CVE-2023-50231CriMay 3, 2024
    risk 0.67cvss 9.6epss 0.53

    NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is…

  • CVE-2024-30568CriApr 3, 2024
    risk 0.67cvss 9.8epss 0.47

    Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

  • CVE-2020-10924HigJul 28, 2020
    risk 0.67cvss 8.8epss 0.87

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2020-10923HigJul 28, 2020
    risk 0.67cvss 8.8epss 0.85

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on…

  • CVE-2016-5649CriJul 24, 2018
    risk 0.66cvss 9.8epss 0.27

    A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin…

  • CVE-2025-4978CriMay 20, 2025
    risk 0.65cvss 9.8epss 0.18

    A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It is possible to initiate…

  • CVE-2025-28219CriMar 28, 2025
    risk 0.65cvss 9.8epss 0.12

    Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.

  • CVE-2023-34563CriJun 20, 2023
    risk 0.65cvss 9.8epss 0.14

    netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.

  • CVE-2023-33532CriJun 6, 2023
    risk 0.65cvss 9.8epss 0.16

    There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.

  • CVE-2023-27853CriMar 10, 2023
    risk 0.65cvss 9.8epss 0.20

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.

  • CVE-2022-4390CriDec 9, 2022
    risk 0.65cvss 10.0epss 0.01

    A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic,…

  • CVE-2021-45630CriDec 26, 2021
    risk 0.65cvss 10.0epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and…

  • CVE-2021-38516CriAug 11, 2021
    risk 0.65cvss 10.0epss 0.01

    Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before 1.0.0.52, D7800 before 1.0.1.44, D8500 before 1.0.3.43, DC112A before 1.0.0.40, DGN2200v4 before 1.0.0.108, RBK50…

  • CVE-2016-1525HigFeb 13, 2016
    risk 0.65cvss 8.6epss 0.75

    Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.

  • CVE-2025-50526CriDec 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

  • CVE-2025-44658CriJul 21, 2025
    risk 0.64cvss 9.8epss 0.01

    In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server…

  • CVE-2025-45492CriMay 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.

  • CVE-2024-57235CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

  • CVE-2024-57234CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

  • CVE-2024-57233CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

  • CVE-2024-57232CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2024-57231CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

  • CVE-2024-57230CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

  • CVE-2024-57229CriMay 5, 2025
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

  • CVE-2025-29044CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Netgear- R61 router V1.0.1.28 allows a remote attacker to execute arbitrary code via the QUERY_STRING key value

  • CVE-2024-54809CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an…

  • CVE-2024-54808CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code…

  • CVE-2024-54807CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted…

  • CVE-2024-54806CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.

  • CVE-2024-54805CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to…

  • CVE-2024-54804CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.

  • CVE-2024-54803CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.

  • CVE-2024-54802CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.

  • CVE-2023-50089CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.04

    A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

Page 1 of 28