VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2019-20724MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before…

  • CVE-2019-20723MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, DM200 before 1.0.0.58, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76,…

  • CVE-2019-20722MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, RBK20 before 2.3.0.28, RBR20 before…

  • CVE-2019-20719MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before 1.0.0.52, D8500 before 1.0.3.43, R6250 before 1.0.4.34, R6400 before 1.0.1.44, R6400v2 before 1.0.2.62, R7000P before…

  • CVE-2019-20718MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before 1.0.0.52, D8500 before 1.0.3.43, R6250 before 1.0.4.34, R6400 before 1.0.1.44, R6400v2 before 1.0.2.62, R7100LG before…

  • CVE-2019-20716MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects DGN2200v4 before 1.0.0.110 and DGND2200Bv4 before 1.0.0.109.

  • CVE-2019-20713MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D8500 before 1.0.3.44, R6250 before 1.0.4.34, R6300v2 before 1.0.4.32, R6400 before 1.0.1.46, R6700 before 1.0.2.6, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R7000…

  • CVE-2019-20712MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R6250 before 1.0.4.34, R6300v2…

  • CVE-2019-20700MedApr 16, 2020
    risk 0.44cvss 6.7epss 0.00

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.44, D6400 before 1.0.0.78, D7000v2 before 1.0.0.51, D8500 before 1.0.3.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.110, EX3700…

  • CVE-2019-20692MedApr 16, 2020
    risk 0.44cvss 6.7epss 0.00

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.44, D6400 before 1.0.0.78, D7000v2 before 1.0.0.51, D8500 before 1.0.3.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, EX3700…

  • CVE-2019-20689MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.72, EX6400 before 1.0.2.136, EX7300…

  • CVE-2019-20688MedApr 16, 2020
    risk 0.44cvss 6.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.72, EX6400…

  • CVE-2019-20651MedApr 15, 2020
    risk 0.44cvss 6.7epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16.

  • CVE-2019-12591MedJun 3, 2019
    risk 0.44cvss 6.8epss 0.01

    NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.

  • CVE-2021-45550MedDec 26, 2021
    risk 0.43cvss 6.6epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.78, D6100 before 1.0.0.63, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DGN2200Bv4 before…

  • CVE-2021-38520MedAug 11, 2021
    risk 0.43cvss 6.6epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, and R7000P before 1.3.2.124.

  • CVE-2025-45493MedDec 23, 2025
    risk 0.42cvss 6.5epss 0.01

    Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

  • CVE-2025-52082MedJul 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the read_access parameter.

  • CVE-2025-52081MedJul 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the usb_folder parameter.

  • CVE-2025-52080MedJul 15, 2025
    risk 0.42cvss 6.5epss 0.00

    In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.

  • CVE-2025-7407MedJul 10, 2025
    risk 0.42cvss 6.3epss 0.09

    A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manipulation of the argument host_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2022-41545MedFeb 18, 2025
    risk 0.42cvss 6.4epss 0.00

    The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does…

  • CVE-2024-12147MedDec 4, 2024
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file upgrade_check.cgi of the component HTTP Header Handler. The manipulation of the argument Content-Length leads to…

  • CVE-2021-34983MedMay 7, 2024
    risk 0.42cvss 6.5epss 0.00

    NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not…

  • CVE-2023-27357MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this…

  • CVE-2023-38924MedAug 7, 2023
    risk 0.42cvss 6.5epss 0.01

    Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi.

  • CVE-2023-2380MedApr 28, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…

  • CVE-2022-38458MedMar 21, 2023
    risk 0.42cvss 6.5epss 0.01

    A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.

  • CVE-2021-34870MedJan 25, 2022
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP…

  • CVE-2021-45671MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.62, EX7500 before 1.0.0.72, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.4.120, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, MR60 before 1.0.6.110, RAX20…

  • CVE-2021-45670MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before 1.0.11.116, R7900 before 1.0.4.38, R8000 before 1.0.4.68,…

  • CVE-2021-45668MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, R7900P before 1.4.1.66,…

  • CVE-2021-45667MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7960P before 1.4.1.66, RAX200 before 1.0.3.106, RBS40V before 2.6.1.4,…

  • CVE-2021-45666MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, RBW30 before 2.6.1.4, RBK752 before 3.2.16.6,…

  • CVE-2021-45665MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, RBW30 before 2.6.1.4, RBK752 before 3.2.16.6,…

  • CVE-2021-45647MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EAX80 before 1.0.1.62, EX7000 before 1.0.1.104, R6120 before 1.0.0.76, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260 before 1.1.0.78, R6850 before 1.1.0.78, R6350 before 1.1.0.78,…

  • CVE-2021-45608MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.03

    Certain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated attacker. Remote code execution from the WAN interface (TCP port 20005) cannot be ruled out; however, exploitability was judged to be of "rather…

  • CVE-2021-45519MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.

  • CVE-2021-45518MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.

  • CVE-2021-45517MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.

  • CVE-2021-45515MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by denial of service. This affects EX7500 before 1.0.0.72, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, RBRE960 before 6.0.3.68, RBSE960 before 6.0.3.68, RBR750 before 3.2.17.12, RBR850 before 3.2.17.12, RBS750 before 3.2.17.12, RBS850 before…

  • CVE-2021-45498MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.02

    NETGEAR R6700v2 devices before 1.2.0.88 are affected by authentication bypass.

  • CVE-2021-45495MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.02

    NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.

  • CVE-2021-41788MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.02

    MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

  • CVE-2020-35233MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.01

    The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.

  • CVE-2020-35224MedMar 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticated attackers to force a device reboot.

  • CVE-2021-27257MedMar 5, 2021
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2020-27873MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SOAP API endpoint, which…

  • CVE-2020-35791MedDec 30, 2020
    risk 0.42cvss 6.4epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, R8900 before 1.0.5.2, and R9000 before 1.0.5.2.

  • CVE-2020-35790MedDec 30, 2020
    risk 0.42cvss 6.4epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.

Page 19 of 28