Skip to main content

Vendor/product archive

netgear / xr300_firmware CVEs

Beta · best-effort

40 CVEs tagged to netgear / xr300_firmware5 Critical, 9 High, 26 Medium, 0 Low, 0 Unrated.

CVE-2022-40620

Published Jan 28, 2026

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its aut…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-40619

Published Jan 28, 2026

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnera…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-52082

Published Jul 15, 2025

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST re…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52081

Published Jul 15, 2025

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when proc…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52080

Published Jul 15, 2025

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when proc…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-52018

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute a…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52017

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51022

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Ser…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51016

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allows attackers to cause a Denial of Service…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51014

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid_an parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51008

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arb…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51007

Published Nov 5, 2024

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers to cause a Denial of Service (…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2