Skip to main content

Vendor archive

netgear CVEs

Beta · best-effort

1,334 CVEs tagged to vendor netgear199 Critical, 561 High, 536 Medium, 38 Low, 0 Unrated.

CVE-2026-0419

Published Jun 9, 2026

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operat…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0414

Published Jun 9, 2026

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of ro…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0412

Published Jun 9, 2026

Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0411

Published Jun 9, 2026

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi r…

CVSS 4.2 · Medium
evidence mentions
6
Buzz score
29.5

CVE-2022-40620

Published Jan 28, 2026

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its aut…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-40619

Published Jan 28, 2026

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnera…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-0406

Published Jan 13, 2026

An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections.

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,334 CVEsPage 1 of 54