Skip to main content

Vendor archive

netgear CVEs

Beta · best-effort

1,334 CVEs tagged to vendor netgear199 Critical, 561 High, 536 Medium, 38 Low, 0 Unrated.

CVE-2022-36429

Published Mar 21, 2023

A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arb…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28338

Published Mar 15, 2023

Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28337

Published Mar 15, 2023

When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1327

Published Mar 14, 2023

Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27853

Published Mar 10, 2023

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27852

Published Mar 10, 2023

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27851

Published Mar 10, 2023

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the dev…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27850

Published Mar 10, 2023

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1205

Published Mar 10, 2023

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0849

Published Feb 15, 2023

A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0848

Published Feb 15, 2023

A vulnerability was found in Netgear WNDR3700v2 1.0.1.14. It has been rated as problematic. This issue affects some unknown processing of the component Web Management Interface. T…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48322

Published Feb 13, 2023

NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P befo…

CVSS 9.8 · Critical

CVE-2022-48176

Published Jan 31, 2023

Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack over…

CVSS 7.8 · High

CVE-2022-46424

Published Dec 20, 2022

An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46423

Published Dec 20, 2022

An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-upl…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46422

Published Dec 20, 2022

An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware upd…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47210

Published Dec 16, 2022

The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-47209

Published Dec 16, 2022

A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user vi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-47208

Published Dec 16, 2022

The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segme…

CVSS 8.8 · High

CVE-2022-4390

Published Dec 9, 2022

A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these device…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,334 CVEsPage 11 of 54