VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2020-35786MedDec 30, 2020
    risk 0.29cvss 4.5epss 0.00

    NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user.

  • CVE-2018-21141MedApr 21, 2020
    risk 0.29cvss 4.5epss 0.00

    Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54,…

  • CVE-2019-20744MedApr 16, 2020
    risk 0.29cvss 4.5epss 0.00

    NETGEAR WAC510 devices before 5.0.10.2 are affected by disclosure of sensitive information.

  • CVE-2019-20729MedApr 16, 2020
    risk 0.29cvss 4.4epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JNDR3000 before 1.0.0.22, R6250 before 1.0.4.26, R6300v2 before 1.0.4.22, R6400 before 1.0.1.36, R6400v2 before 1.0.2.52, R6700 before 1.0.1.44, R6900 before 1.0.1.44, R7000 before…

  • CVE-2026-9214MedAug 11, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

  • CVE-2026-11738MedAug 11, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

  • CVE-2026-11737MedAug 11, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.

  • CVE-2026-0418MedJun 9, 2026
    risk 0.28cvss epss 0.00

    Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

  • CVE-2026-0417MedJun 9, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

  • CVE-2026-0416MedJun 9, 2026
    risk 0.28cvss epss 0.00

    An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of…

  • CVE-2026-0415MedJun 9, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

  • CVE-2026-0414MedJun 9, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

  • CVE-2026-0413MedJun 9, 2026
    risk 0.28cvss epss 0.00

    A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

  • CVE-2026-0412MedJun 9, 2026
    risk 0.28cvss epss 0.00

    Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached…

  • CVE-2024-1431MedFeb 11, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit…

  • CVE-2024-1430MedFeb 11, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web Management Interface. The manipulation leads to information…

  • CVE-2023-2396MedApr 28, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Netgear SRX5308 up to 4.3.5-3. This vulnerability affects unknown code of the component Web Management Interface. The manipulation of the argument USERDBUsers.Password leads to cross site scripting. The attack can be…

  • CVE-2023-2395MedApr 28, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the component Web Management Interface. The manipulation of the argument Login.userAgent leads to cross site scripting. It is possible to initiate the…

  • CVE-2021-45676MedDec 26, 2021
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.5.126, RAX20 before 1.0.2.82, RAX80 before 1.0.5.126, RAX15 before 1.0.2.82, and RAX75 before 1.0.5.126.

  • CVE-2021-38536MedAug 11, 2021
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76,…

  • CVE-2021-38535MedAug 11, 2021
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76,…

  • CVE-2021-38526MedAug 11, 2021
    risk 0.28cvss 4.3epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX35 before 1.0.3.94, RAX38 before 1.0.3.94, and RAX40 before 1.0.3.94.

  • CVE-2020-35778MedDec 30, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects GS716Tv3 before 6.3.1.36 and GS724Tv4 before 6.3.1.36.

  • CVE-2020-26923MedOct 9, 2020
    risk 0.28cvss 4.3epss 0.01

    Certain NETGEAR devices are affected by stored XSS. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.

  • CVE-2020-5621MedAug 28, 2020
    risk 0.28cvss 4.3epss 0.01

    Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the…

  • CVE-2016-11055MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-01-11, JWNR2010v3 before 2017-01-11,…

  • CVE-2018-21095MedApr 27, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects SRR60 before 2.2.1.210 and SRS60 before 2.2.1.210.

  • CVE-2017-18710MedApr 24, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R8300 before 1.0.2.106 and R8500 before 1.0.2.106.

  • CVE-2019-20663MedApr 15, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

  • CVE-2019-20662MedApr 15, 2020
    risk 0.28cvss 4.3epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

  • CVE-2026-0411MedJun 9, 2026
    risk 0.27cvss epss 0.00

    An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without…

  • CVE-2021-45672MedDec 26, 2021
    risk 0.27cvss 4.2epss 0.00

    Certain NETGEAR devices are affected by Stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6220 before 1.1.0.110, R6230 before 1.1.0.110, R6260 before 1.1.0.78, R6800 before 1.2.0.76,…

  • CVE-2021-38537MedAug 11, 2021
    risk 0.27cvss 4.2epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1.2.0.76, R6800 before 1.2.0.76, R6900v2 before 1.2.0.76,…

  • CVE-2021-38534MedAug 11, 2021
    risk 0.27cvss 4.1epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6100 before 1.0.0.60, D6200 before 1.1.00.36, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44,…

  • CVE-2020-26918MedOct 9, 2020
    risk 0.27cvss 4.1epss 0.01

    Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before…

  • CVE-2020-26917MedOct 9, 2020
    risk 0.27cvss 4.1epss 0.01

    Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before…

  • CVE-2017-18808MedApr 21, 2020
    risk 0.27cvss 4.2epss 0.00

    NETGEAR ReadyNAS OS 6 devices running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings.

  • CVE-2024-36795MedJun 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

  • CVE-2021-45653LowDec 26, 2021
    risk 0.25cvss 3.9epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

  • CVE-2021-45640LowDec 26, 2021
    risk 0.25cvss 3.9epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1.1.00.34, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.74, D7000v2 before 1.0.0.53, D7800 before…

  • CVE-2021-45669LowDec 26, 2021
    risk 0.24cvss 3.7epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects RAX200 before 1.0.3.106, MR60 before 1.0.6.110, RAX20 before 1.0.2.82, RAX45 before 1.0.2.72, RAX80 before 1.0.3.106, MS60 before 1.0.6.110, RAX15 before 1.0.2.82, RAX50 before 1.0.2.72, RAX75 before 1.0.3.106,…

  • CVE-2017-2137LowApr 28, 2017
    risk 0.24cvss 3.7epss 0.01

    ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.

  • CVE-2019-20648LowApr 15, 2020
    risk 0.23cvss 3.5epss 0.00

    NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.

  • CVE-2021-45674LowDec 26, 2021
    risk 0.21cvss 3.2epss 0.00

    Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.

  • CVE-2020-26930LowOct 9, 2020
    risk 0.21cvss 3.3epss 0.01

    NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.

  • CVE-2020-26925LowOct 9, 2020
    risk 0.21cvss 3.2epss 0.00

    NETGEAR GS808E devices before 1.7.1.0 are affected by denial of service.

  • CVE-2017-18819LowApr 21, 2020
    risk 0.21cvss 3.3epss 0.00

    NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by incorrect configuration of security settings.

  • CVE-2017-18824LowApr 20, 2020
    risk 0.21cvss 3.3epss 0.01

    Certain NETGEAR devices are affected by directory traversal. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ before 12.0.2.15, M4300-52G-POE+ before 12.0.2.15, M4300-8X8F before 12.0.2.15, M4300-12X12F before 12.0.2.15, M4300-24X24F before…

  • CVE-2021-45648LowDec 26, 2021
    risk 0.20cvss 3.1epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EX6100v2 before 1.0.1.106, EX6150v2 before 1.0.1.106, EX6250 before 1.0.0.146, EX6400 before 1.0.2.164, EX6400v2 before 1.0.0.146, EX6410 before 1.0.0.146, EX6420 before 1.0.0.146, EX7300…

  • CVE-2020-26924LowOct 9, 2020
    risk 0.20cvss 3.1epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC720 before 3.9.1.13 and WAC730 before 3.9.1.13.