Vulnerability index

Browse CVEs

287 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

R6700 Firmware HIGH 8.8
CVE-2021-45732

Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipu…

Mitigation only
Fix from $1,950 2021-12-30
R6700 Firmware HIGH 7.5
CVE-2021-45077

Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services…

Mitigation only
Fix from $1,950 2021-12-30
Rax43 Firmware HIGH 8.8
CVE-2021-20166

Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router container…

Mitigation only
Fix from $1,950 2021-12-30
Rax43 Firmware HIGH 8.8
CVE-2021-20170

Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configu…

Mitigation only
Fix from $1,950 2021-12-30
R6700 Firmware HIGH 8.8
CVE-2021-20173

Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system up…

No fix yet
Fix from $1,950 2021-12-30
Rax43 Firmware HIGH 8.0
CVE-2021-20167EPSS 8%

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the n…

Mitigation only
Fix from $1,950 2021-12-30
Genie Installer HIGH 7.8
CVE-2021-20172

All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of…

No fix yet
Fix from $1,950 2021-12-30
R6700 Firmware HIGH 7.5
CVE-2021-20174

Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from t…

Mitigation only
Fix from $1,950 2021-12-30
R6700 Firmware HIGH 7.5
CVE-2021-20175

Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from …

Mitigation only
Fix from $1,950 2021-12-30
Rax43 Firmware MEDIUM 6.8
CVE-2021-20168

Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is ab…

Mitigation only
Fix from $1,600 2021-12-30
Rax43 Firmware MEDIUM 6.8
CVE-2021-20169

Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent …

Mitigation only
Fix from $1,600 2021-12-30
R6700 Firmware MEDIUM 6.8
CVE-2021-23147

Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the de…

Mitigation only
Fix from $1,600 2021-12-30
Rax43 Firmware MEDIUM 5.5
CVE-2021-20171

Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored…

Mitigation only
Fix from $1,600 2021-12-30
R6400v2 Firmware HIGH 8.1
CVE-2021-40847EPSS 10%

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root…

No fix yet
Fix from $1,950 2021-09-21
R6020 Firmware HIGH 7.2
CVE-2021-41383

setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.

No fix yet
Fix from $1,950 2021-09-17
Prosafe Network Management System CRITICAL 9.8
CVE-2021-27274EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…

Mitigation only
Fix from $2,300 2021-03-29
Prosafe Network Management System HIGH 8.8
CVE-2021-27273EPSS 65%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…

Mitigation only
Fix from $1,950 2021-03-29
Prosafe Network Management System HIGH 8.3
CVE-2021-27275EPSS 73%

This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE …

Mitigation only
Fix from $1,950 2021-03-29
Prosafe Network Management System HIGH 7.1
CVE-2021-27272EPSS 74%

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…

Mitigation only
Fix from $1,950 2021-03-29
Prosafe Network Management System HIGH 7.1
CVE-2021-27276EPSS 72%

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…

Mitigation only
Fix from $1,950 2021-03-29
Gs116e Firmware HIGH 8.8
CVE-2020-35229

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can b…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware HIGH 8.8
CVE-2020-35231

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to by…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware HIGH 7.2
CVE-2020-35227

A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware HIGH 7.1
CVE-2020-35226

NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write re…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware MEDIUM 6.8
CVE-2020-35230

Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer p…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware MEDIUM 6.5
CVE-2020-35233

The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device re…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware HIGH 8.8
CVE-2020-35223

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omittin…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware MEDIUM 6.8
CVE-2020-35225

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in w…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware MEDIUM 6.5
CVE-2020-35224

A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticat…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware HIGH 8.8
CVE-2020-35221

The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing …

Mitigation only
Fix from $1,950 2021-03-10