VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2024-51008HigNov 5, 2024
    risk 0.52cvss 8.0epss 0.01

    Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

  • CVE-2024-51005HigNov 5, 2024
    risk 0.52cvss 8.0epss 0.01

    Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

  • CVE-2024-50993HigNov 5, 2024
    risk 0.52cvss 8.0epss 0.01

    Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

  • CVE-2023-27367HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability,…

  • CVE-2023-27361HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is required to exploit this…

  • CVE-2023-27356HigMay 3, 2024
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the…

  • CVE-2024-30572HigApr 3, 2024
    risk 0.52cvss 8.0epss 0.01

    Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.

  • CVE-2022-27647HigMar 29, 2023
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2021-27276HigMar 29, 2021
    risk 0.52cvss 7.1epss 0.72

    This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2021-27272HigMar 29, 2021
    risk 0.52cvss 7.1epss 0.74

    This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2020-35787HigDec 30, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.36, D7000 before 1.0.1.70, EX6200v2 before 1.0.1.78, EX7000 before 1.0.1.78, EX8000 before 1.0.1.186, JR6150 before…

  • CVE-2017-18861HigApr 28, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and earlier.

  • CVE-2018-21100HigApr 27, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

  • CVE-2018-21099HigApr 27, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

  • CVE-2018-21101HigApr 23, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

  • CVE-2017-18758HigApr 22, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

  • CVE-2018-21120HigApr 22, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,…

  • CVE-2019-20761HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.02

    NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

  • CVE-2019-20758HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.00

    NETGEAR R7000 devices before 1.0.9.42 are affected by a buffer overflow by an authenticated user.

  • CVE-2019-20711HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20710HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20709HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20708HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20707HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

  • CVE-2019-20706HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.02

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

  • CVE-2019-20705HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20704HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20703HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20702HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20701HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20680HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before…

  • CVE-2019-20657HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.28, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.24, JR6150 before 1.0.1.24, R6120 before…

  • CVE-2019-20642HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass.

  • CVE-2026-0405HigJan 13, 2026
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

  • CVE-2024-5245HigMay 23, 2024
    risk 0.51cvss 7.8epss 0.01

    NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. An attacker must first obtain the…

  • CVE-2023-49694HigNov 29, 2023
    risk 0.51cvss 7.8epss 0.01

    A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory. The user can then execute the JSP files under the security context of SYSTEM.

  • CVE-2022-48176HigJan 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.

  • CVE-2022-47210HigDec 16, 2022
    risk 0.51cvss 7.8epss 0.00

    The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary…

  • CVE-2022-37234HigSep 22, 2022
    risk 0.51cvss 7.8epss 0.01

    Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.

  • CVE-2022-24655HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.

  • CVE-2021-20172HigDec 30, 2021
    risk 0.51cvss 7.8epss 0.00

    All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the…

  • CVE-2021-45649HigDec 26, 2021
    risk 0.51cvss 7.9epss 0.00

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R7000 before 1.0.11.126, R6900P before 1.3.2.126, and R7000P before 1.3.2.126.

  • CVE-2021-45534HigDec 26, 2021
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects AC2100 before 1.2.0.88, AC2400 before 1.2.0.88, AC2600 before 1.2.0.88, D7000 before 1.0.1.82, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260 before 1.1.0.84, R6330 before…

  • CVE-2021-40867HigSep 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who uses the same source IP address as an admin in the process of logging in (e.g., behind the same NAT device, or already in possession of a…

  • CVE-2017-18709HigApr 24, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R8300 before 1.0.2.94 and R8500 before 1.0.2.94.

  • CVE-2017-18787HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050, before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and…

  • CVE-2017-18786HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and…

  • CVE-2017-18779HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by a buffer overflow. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080…

  • CVE-2017-18777HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before V1.0.3.29, DGN2200v4 before 1.0.0.82, DGN2200Bv4 before 1.0.0.82, R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before…

  • CVE-2017-18837HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

Page 13 of 28