VYPR

Vendor CVEs

Netgear

All CVEs

1,377 total · sorted by risk
  • CVE-2024-4235LowApr 26, 2024
    risk 0.18cvss 2.7epss 0.01

    A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads to cleartext storage of sensitive information. The attack can be initiated remotely. The…

  • CVE-2023-0850LowFeb 15, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown processing of the component Web Interface. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2019-19964LowMar 23, 2020
    risk 0.18cvss 2.7epss 0.01

    On NETGEAR GS728TPS devices through 5.3.0.35, a remote attacker having network connectivity to the web-administration panel can access part of the web panel, bypassing authentication.

  • CVE-2023-2394LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument wanName leads to cross site scripting. The attack may be…

  • CVE-2023-2393LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the…

  • CVE-2023-2392LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been classified as problematic. Affected is an unknown function of the file scgi-bin/platform.cgi?page=time_zone.htm of the component Web Management Interface. The manipulation of the argument ManualDate.minutes…

  • CVE-2023-2391LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. This issue affects some unknown processing of the file scgi-bin/platform.cgi?page=time_zone.htm of the component Web Management Interface. The manipulation of the argument ntp.server2 leads…

  • CVE-2023-2390LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability has been found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. This vulnerability affects unknown code of the file scgi-bin/platform.cgi?page=time_zone.htm of the component Web Management Interface. The manipulation of the argument ntp.server1…

  • CVE-2023-2389LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-2388LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability, which was classified as problematic, has been found in Netgear SRX5308 up to 4.3.5-3. Affected by this issue is some unknown functionality of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation…

  • CVE-2023-2387LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability classified as problematic was found in Netgear SRX5308 up to 4.3.5-3. Affected by this vulnerability is an unknown functionality of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-2386LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.toAddr…

  • CVE-2023-2385LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been rated as problematic. This issue affects some unknown processing of the file scgi-bin/platform.cgi?page=ike_policies.htm of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-2384LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been declared as problematic. This vulnerability affects unknown code of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-2383LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been classified as problematic. This affects an unknown part of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-2382LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. Affected by this issue is some unknown functionality of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the…

  • CVE-2023-2381LowApr 28, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability has been found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file scgi-bin/platform.cgi?page=bandwidth_profile.htm of the component Web Management Interface. The manipulation of…

  • CVE-2021-38514LowAug 11, 2021
    risk 0.16cvss 2.4epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.52, D7800 before…

  • CVE-2026-11736LowAug 11, 2026
    risk 0.12cvss epss 0.00

    A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.

  • CVE-2026-11735LowAug 11, 2026
    risk 0.12cvss epss 0.00

    A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.

  • CVE-2026-0410LowJun 9, 2026
    risk 0.12cvss epss 0.00

    Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

  • CVE-2013-2751Dec 12, 2013
    risk 0.09cvss epss 0.72

    Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to execute arbitrary Perl code via a crafted request, related to the "forgot password workflow."

  • CVE-2026-11734LowAug 11, 2026
    risk 0.07cvss epss 0.00

    A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

  • CVE-2026-11733LowAug 11, 2026
    risk 0.07cvss epss 0.00

    A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.

  • CVE-2006-6059Nov 22, 2006
    risk 0.05cvss epss 0.19

    Buffer overflow in MA521nd5.SYS driver 5.148.724.2003 for NetGear MA521 PCMCIA adapter allows remote attackers to execute arbitrary code via (1) beacon or (2) probe 802.11 frame responses with an long supported rates information element. NOTE: this issue was reported as a…

  • CVE-2006-5972Nov 18, 2006
    risk 0.05cvss epss 0.19

    Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.11 beacon request.

  • CVE-2014-4927Jul 24, 2014
    risk 0.04cvss epss 0.11

    Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.

  • CVE-2013-4776Dec 19, 2013
    risk 0.04cvss epss 0.07

    NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a denial of service (reboot or crash) via a crafted HTTP request to filesystem/.

  • CVE-2013-4775Dec 19, 2013
    risk 0.04cvss epss 0.15

    NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to…

  • CVE-2009-2258Jun 30, 2009
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.

  • CVE-2009-2257Jun 30, 2009
    risk 0.04cvss epss 0.07

    The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and…

  • CVE-2009-2256Jun 30, 2009
    risk 0.04cvss epss 0.07

    The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.

  • CVE-2009-0680Feb 22, 2009
    risk 0.04cvss epss 0.08

    cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences.

  • CVE-2006-6125Nov 27, 2006
    risk 0.04cvss epss 0.14

    Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID.

  • CVE-2008-6122Feb 11, 2009
    risk 0.03cvss epss 0.03

    The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question mark ("?").

  • CVE-2007-5562Oct 18, 2007
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in cgi-bin/welcome (aka the login page) in Netgear SSL312 PROSAFE SSL VPN-Concentrator 25 allows remote attackers to inject arbitrary web script or HTML via the err parameter in the context of an error page.

  • CVE-2004-2032May 24, 2004
    risk 0.03cvss epss 0.03

    Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.

  • CVE-2003-1427Dec 31, 2003
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

  • CVE-2026-62659MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings

  • CVE-2026-62658MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.

  • CVE-2026-62657MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.

  • CVE-2026-62656MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.

  • CVE-2026-62655MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable.

  • CVE-2026-15757MedJul 14, 2026
    risk 0.00cvss epss 0.00

    A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the…

  • CVE-2014-4864Sep 10, 2014
    risk 0.00cvss epss 0.01

    The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive information by reading a file.

  • CVE-2014-2969Jul 7, 2014
    risk 0.00cvss epss 0.02

    NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote attackers to upload firmware or read or modify memory contents, and consequently execute arbitrary code, via a request to (1)…

  • CVE-2013-3069Apr 25, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1) UserName or (2) Password to the NAS User Setup page, (3) deviceName to USB_advanced.htm, or (4)…

  • CVE-2013-2752Dec 12, 2013
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijack the authentication of users.

  • CVE-2012-2439Apr 28, 2012
    risk 0.00cvss epss 0.02

    The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown vectors.

  • CVE-2011-1674Apr 10, 2011
    risk 0.00cvss epss 0.03

    The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visiting recreate.php and then visiting index.php.

Page 27 of 28