VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2023-49007CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.09

    In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.

  • CVE-2023-49693CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

  • CVE-2023-36187CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.

  • CVE-2023-38928CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.

  • CVE-2023-30280CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.

  • CVE-2023-1327CriMar 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.

  • CVE-2023-27852CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.

  • CVE-2022-48322CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

  • CVE-2022-44184CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

  • CVE-2022-44200CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.

  • CVE-2022-44199CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

  • CVE-2022-44198CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

  • CVE-2022-44197CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

  • CVE-2022-44196CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

  • CVE-2022-44194CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.

  • CVE-2022-44193CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.

  • CVE-2022-44191CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

  • CVE-2022-44190CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

  • CVE-2022-44188CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

  • CVE-2022-44187CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

  • CVE-2022-44186CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.

  • CVE-2022-37235CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

  • CVE-2022-37232CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

  • CVE-2022-31937CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

  • CVE-2021-34236CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'.

  • CVE-2021-45678CriDec 26, 2021
    risk 0.64cvss 9.8epss 0.01

    NETGEAR RAX200 devices before 1.0.5.132 are affected by insecure code.

  • CVE-2021-45617CriDec 26, 2021
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX7500 before 1.0.0.72, R6400 before 1.0.1.68, R6900P before 1.3.2.132, R7000 before 1.0.11.116, R7000P…

  • CVE-2021-40866CriSep 13, 2021
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (disabled by default) /sqfs/bin/sccd daemon, which fails to check authentication when the authentication TLV is missing from a received NSDP packet. This affects…

  • CVE-2021-32122CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44.

  • CVE-2021-35973CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.03

    NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This…

  • CVE-2021-27274CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.08

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MFileUploadController class.…

  • CVE-2021-29068CriMar 23, 2021
    risk 0.64cvss 9.9epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7000 before 1.0.11.106, R6900P before 1.3.2.124, R7000P before 1.3.2.124, R7900 before 1.0.4.26, R7850 before 1.0.5.60, R8000…

  • CVE-2020-35797CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.

  • CVE-2020-35795CriDec 30, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D7800 before 1.0.1.58, EAX20 before 1.0.0.36, EAX80 before…

  • CVE-2020-15636CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.09

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900, R8000, RS400, and XR300 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2017-18858CriApr 28, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300-52G 12.0.2.11 and earlier, M4300-28G-POE+ 12.0.2.11 and earlier, M4300-52G-POE+ 12.0.2.11 and earlier, M4300-8X8F 12.0.2.11 and…

  • CVE-2017-18857CriApr 28, 2020
    risk 0.64cvss 9.8epss 0.01

    The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.

  • CVE-2018-21153CriApr 27, 2020
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, EX2700 before 1.0.1.32, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.70, EX6200v2 before 1.0.1.62, EX6400 before 1.0.1.78,…

  • CVE-2018-21097CriApr 27, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WAC120 before 2.1.7, WN604 before 3.3.10, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before…

  • CVE-2018-21162CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6250 before 1.0.4.8, R6300v2 before 1.0.4.6, R6400 before 1.0.1.12, R6700 before 1.0.1.16, R7000 before…

  • CVE-2018-21161CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.34, R7800 before 1.0.2.46, and R9000 before 1.0.3.16.

  • CVE-2018-21137CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by a hardcoded password. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

  • CVE-2018-21134CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6700 before 1.0.1.48, R7900 before 1.0.2.16, R6900 before 1.0.1.48, R7000P before 1.3.1.44, R6900P before 1.3.1.44, R6250 before 1.0.4.30, R6300v2 before 1.0.4.32,…

  • CVE-2018-21133CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2018-21132CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2019-20730CriApr 16, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by SQL injection. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6200 before 1.1.00.28, D6220 before 1.0.0.40, D6400 before 1.0.0.74, D7000 before 1.0.1.60, D7000v2 before 1.0.0.74, D7800 before 1.0.1.34, D8500 before 1.0.3.39,…

  • CVE-2019-20699CriApr 16, 2020
    risk 0.64cvss 9.8epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS408EPP before 1.0.0.15, GS808E before 1.7.0.7, GS908E before 1.7.0.3, GSS108E before 1.6.0.4, and GSS108EPP before 1.0.0.15.

  • CVE-2019-20679CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.01

    NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.

  • CVE-2020-11790CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR R7800 devices before 1.0.2.68 are affected by remote code execution by unauthenticated attackers.

  • CVE-2020-11789CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

Page 2 of 28