VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2017-18830HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18829HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18826HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18822HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F…

  • CVE-2017-18849HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R6900P before…

  • CVE-2017-18845HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38.

  • CVE-2017-18844HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.

  • CVE-2017-18843HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50.

  • CVE-2017-18838HigApr 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before…

  • CVE-2019-20655HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.

  • CVE-2022-40620HigJan 28, 2026
    risk 0.50cvss 7.7epss 0.00

    FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update…

  • CVE-2022-40619HigJan 28, 2026
    risk 0.50cvss 7.7epss 0.02

    FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This…

  • CVE-2013-10061HigAug 1, 2025
    risk 0.50cvss 7.2epss 0.04

    An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling…

  • CVE-2013-10060HigAug 1, 2025
    risk 0.50cvss 7.2epss 0.05

    An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A remote attacker with valid credentials can execute arbitrary commands via crafted input to the…

  • CVE-2024-30571HigApr 3, 2024
    risk 0.50cvss 7.5epss 0.14

    An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

  • CVE-2021-45595HigDec 26, 2021
    risk 0.50cvss 7.6epss 0.02

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, RBS10 before 2.7.3.22, RBS20 before…

  • CVE-2021-45551HigDec 26, 2021
    risk 0.50cvss 7.6epss 0.02

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, R6220 before…

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2017-18860HigApr 29, 2020
    risk 0.50cvss 7.7epss 0.01

    Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP…

  • CVE-2026-24714HigJan 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box.

  • CVE-2025-12946HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are…

  • CVE-2025-12943HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute…

  • CVE-2025-12942HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform MiTM attacks and control over DNS Server to perform command execution.This issue affects R6260: through 1.1.0.86; R6850: through…

  • CVE-2025-44652HigJul 21, 2025
    risk 0.49cvss 7.5epss 0.01

    In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.

  • CVE-2025-44650HigJul 21, 2025
    risk 0.49cvss 7.5epss 0.01

    In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.

  • CVE-2023-51634HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30 routers. Authentication is not required to…

  • CVE-2024-30569HigApr 3, 2024
    risk 0.49cvss 7.5epss 0.02

    An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

  • CVE-2024-28340HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

  • CVE-2023-28338HigMar 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A sufficiently large file will cause device…

  • CVE-2023-24498HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.

  • CVE-2022-38955HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.00

    An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the CRC check. A successful attack can either introduce a backdoor to the…

  • CVE-2021-44262HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.

  • CVE-2021-45077HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary configuration file…

  • CVE-2021-20175HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and…

  • CVE-2021-20174HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be…

  • CVE-2021-45642HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.64, EX6250 before 1.0.0.134, EX7700 before 1.0.0.222, LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, R8900 before 1.0.5.26, R9000 before 1.0.5.26, XR450 before…

  • CVE-2021-45557HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TUP before 1.0.5.3, GS710TUP before 1.0.5.3, GS308T…

  • CVE-2021-45556HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.36, GS110TPP before 7.0.7.2, GS110TPv2 before 5.4.2.36., GS110TPv3 before 7.0.7.2, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS724TPP before 2.0.6.3,…

  • CVE-2021-45524HigDec 26, 2021
    risk 0.49cvss 7.6epss 0.01

    NETGEAR R8000 devices before 1.0.4.62 are affected by a buffer overflow by an authenticated user.

  • CVE-2021-45511MedDec 26, 2021
    risk 0.49cvss 6.8epss 0.18

    Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08-27, D7000 before 2021-08-27, R6220 before 2021-08-27, R6230 before 2021-08-27, R6260 before 2021-08-27, R6330 before 2021-08-27,…

  • CVE-2021-45493HigDec 26, 2021
    risk 0.49cvss 7.6epss 0.01

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

  • CVE-2021-29073HigMar 23, 2021
    risk 0.49cvss 7.6epss 0.00

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R8000P before 1.4.1.66, MK62 before 1.0.6.110, MR60 before 1.0.6.110, MS60 before 1.0.6.110, R7960P before 1.4.1.66, R7900P before 1.4.1.66, RAX15 before 1.0.2.82, RAX20…

  • CVE-2020-35804HigDec 30, 2020
    risk 0.49cvss 7.6epss 0.00

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7800 before 1.0.1.58, R7800 before 1.0.2.74, R8900 before 1.0.5.18, R9000 before 1.0.5.18, and XR700 before 1.0.1.34.

  • CVE-2020-35802HigDec 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.14, RBW30 before 2.6.1.4, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6,…

  • CVE-2020-35788HigDec 30, 2020
    risk 0.49cvss 7.6epss 0.00

    NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.

  • CVE-2020-35779HigDec 30, 2020
    risk 0.49cvss 7.5epss 0.01

    NETGEAR NMS300 devices before 1.6.0.27 are affected by denial of service.

  • CVE-2020-26912HigOct 9, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2…

  • CVE-2017-18859HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by slowdown/stoppage. This affects C6300 before 2017-05-30, CM400 before 2017-05-30, CM700 before 2017-05-30, and CMD31T before 2017-05-30.

  • CVE-2016-11060HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by insecure renegotiation. This affects SRX5308 before 2017-02-10, FVS336Gv3 before 2017-02-10, FVS318N before 2017-02-10, and FVS318Gv2 before 2017-02-10.

  • CVE-2016-11059HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1500 before 2017-01-06, D3600 before 2017-01-06, D6000 before 2017-01-06, D6100 before 2017-01-06, D6200 before 2017-01-06, D6200B…

Page 14 of 28