VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2020-35783MedDec 30, 2020
    risk 0.42cvss 6.5epss 0.02

    Certain NETGEAR devices are affected by lack of access control at the function level. This affects JGS516PE before 2.6.0.48, GS116Ev2 before 2.6.0.48, JGS524Ev2 before 2.6.0.48, and JGS524PE before 2.6.0.48. The NSDP protocol version allows unauthenticated remote attackers to…

  • CVE-2020-5641MedNov 24, 2020
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without the user's intention or consent via unspecified vectors.

  • CVE-2020-28041MedNov 2, 2020
    risk 0.42cvss 6.5epss 0.02

    The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim visits an attacker-controlled web site with a modern browser, aka NAT…

  • CVE-2020-17409MedOct 13, 2020
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6260, R6220, R6020, JNR3210, and WNR2020 routers with firmware 1.0.66. Authentication is not required to exploit this vulnerability. The…

  • CVE-2020-26922MedOct 9, 2020
    risk 0.42cvss 6.4epss 0.00

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.

  • CVE-2020-10930MedJul 28, 2020
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of URLs. The…

  • CVE-2020-11550MedMay 18, 2020
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote…

  • CVE-2017-18853MedApr 29, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and earlier, R6400v2 1.0.2.18 and earlier, R6700 1.0.1.22 and earlier, R6900 1.0.1.20…

  • CVE-2017-18862MedApr 28, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects JGS516PE before 2017-05-11, JGS524Ev2 before 2017-05-11, JGS524PE before 2017-05-11, GS105Ev2 before 2017-05-11, GS105PE before 2017-05-11, GS108Ev3 before 2017-05-11, GS108PEv3 before 2017-05-11,…

  • CVE-2018-21229MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R7500v2 before 1.0.3.20, R7800 before 1.0.2.38, WN3000RPv3 before 1.0.2.50, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.

  • CVE-2017-18704MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.16, R6300v2 before 1.0.4.18, R6400 before 1.01.32, R6400v2 before 1.0.2.44, R6700 before…

  • CVE-2017-18714MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.00

    NETGEAR WNDR4500v3 devices before 1.0.0.48 are affected by denial of service.

  • CVE-2017-18713MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and…

  • CVE-2017-18712MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and…

  • CVE-2017-18706MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6100 before 1.0.1.20, R7500 before 1.0.0.118, WNDR3700v4 before 1.0.2.88, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before…

  • CVE-2017-18747MedApr 23, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6000 before 1.0.0.24, EX6130 before 1.0.0.16, EX6400 before 1.0.1.60, EX7000 before 1.0.0.50, EX7300 before 1.0.1.60, and…

  • CVE-2017-18746MedApr 23, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6000 before 1.0.0.24, EX6130 before 1.0.0.16, EX6400 before 1.0.1.60, EX7000 before 1.0.0.50, EX7300 before 1.0.1.60, and…

  • CVE-2017-18741MedApr 23, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6250 before 1.0.4.8, R6300v2 before 1.0.4.8, R6700 before 1.0.1.20, R7000 before 1.0.7.10, R7000P before 1.0.0.58, R6900P before 1.0.0.58, R7100LG before 1.0.0.32, R7900 before…

  • CVE-2018-21129MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2017-18752MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before…

  • CVE-2018-21122MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by denial of service. This affects GS110EMX before 1.0.0.9, GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6.

  • CVE-2017-18766MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects DST6501 before 1.1.0.6 and WNR2000v2 before 1.2.0.8.

  • CVE-2017-18765MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by denial of service. This affects R6300v2 before 1.0.4.8, R6400 before 1.0.1.22, R6400v2 before 1.0.2.32, R6700 before 1.0.1.20, R6900 before 1.0.1.20, WNR3500Lv2 before 1.2.0.44, and WNR2000v2 before 1.2.0.8.

  • CVE-2017-18763MedApr 22, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JNR1010v2 before 1.1.0.42, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.42, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6120 before 1.0.0.30, R6220 before 1.1.0.50, R6700v2…

  • CVE-2018-21143MedApr 21, 2020
    risk 0.42cvss 6.5epss 0.01

    NETGEAR GS810EMX devices before 1.0.0.5 are affected by disclosure of sensitive information.

  • CVE-2018-21140MedApr 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

  • CVE-2019-20741MedApr 16, 2020
    risk 0.42cvss 6.5epss 0.01

    NETGEAR WAC510 devices before 5.0.10.2 are affected by disclosure of sensitive information.

  • CVE-2019-20717MedApr 16, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by denial of service. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D7800 before 1.0.1.44, EX2700 before 1.0.1.52, EX6200v2 before 1.0.1.74, EX8000 before 1.0.1.180, R7500v2 before 1.0.3.38, R7800 before 1.0.2.58, RBK20 before…

  • CVE-2019-20698MedApr 16, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC505 before 8.0.5.5 and WAC510 before 8.0.5.5.

  • CVE-2019-20658MedApr 15, 2020
    risk 0.42cvss 6.5epss 0.00

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS108Ev3 before 2.06.08, GS108PEv3 before 2.06.08, GS110EMX before 1.0.1.4, GS116Ev2 before 2.6.0.35, GS408EPP…

  • CVE-2019-20653MedApr 15, 2020
    risk 0.42cvss 6.5epss 0.01

    Certain NETGEAR devices are affected by denial of service. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

  • CVE-2019-20652MedApr 15, 2020
    risk 0.42cvss 6.5epss 0.00

    NETGEAR WAC505 devices before 8.2.1.16 are affected by disclosure of sensitive information.

  • CVE-2019-20638MedApr 15, 2020
    risk 0.42cvss 6.5epss 0.01

    NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.

  • CVE-2012-6341MedFeb 6, 2020
    risk 0.42cvss 6.5epss 0.01

    An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than…

  • CVE-2013-3516MedNov 13, 2019
    risk 0.42cvss 6.5epss 0.01

    NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.

  • CVE-2016-11015MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.

  • CVE-2016-10106MedJan 3, 2017
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thispage parameter, as demonstrated by…

  • CVE-2025-4135MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early…

  • CVE-2025-4122MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early about…

  • CVE-2025-4121MedApr 30, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wireless. The manipulation of the argument host leads to command injection. The attack can be launched remotely. The vendor was…

  • CVE-2023-34284MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-45552MedDec 26, 2021
    risk 0.41cvss 6.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.108, and XR700 before 1.0.1.20.

  • CVE-2021-45548MedDec 26, 2021
    risk 0.41cvss 6.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.60, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.128, EX6400 before 1.0.2.144, EX6400v2…

  • CVE-2021-38539MedAug 11, 2021
    risk 0.41cvss 6.3epss 0.01

    Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before…

  • CVE-2021-38538MedAug 11, 2021
    risk 0.41cvss 6.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK40 before 2.3.5.30, RBR40…

  • CVE-2021-38519MedAug 11, 2021
    risk 0.41cvss 6.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.0.2.8, R7000 before…

  • CVE-2020-15634MedAug 20, 2020
    risk 0.41cvss 6.3epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string…

  • CVE-2020-15417MedJul 28, 2020
    risk 0.41cvss 6.3epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file…

  • CVE-2017-18740MedApr 23, 2020
    risk 0.41cvss 6.3epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.61, D6000 before 1.0.0.61, D6100 before 1.0.0.55, D7800 before 1.0.1.28, R6100 before 1.0.1.16, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before…

  • CVE-2022-47052MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.01

    The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerability using a specially crafted URL.…

Page 20 of 28