Vulnerability index

Browse CVEs

287 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Wnr3500u Firmware CRITICAL 9.8
CVE-2013-4657

Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.

Mitigation only
Fix from $2,300 2019-11-13
Mbr1515 Firmware CRITICAL 9.8
CVE-2019-17373

Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg …

Mitigation only
Fix from $2,300 2019-10-09
Ac1450 Firmware HIGH 8.1
CVE-2019-17372

Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can th…

No fix yet
Fix from $1,950 2019-10-09
Srx5308 Firmware HIGH 7.5
CVE-2019-17049

NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.

No fix yet
Fix from $1,950 2019-09-30
Wnr2000 Firmware HIGH 7.5
CVE-2019-5054

An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0…

No fix yet
Fix from $1,950 2019-09-11
Wnr2000 Firmware HIGH 7.5
CVE-2019-5055

An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version …

No fix yet
Fix from $1,950 2019-09-11
R8000 Firmware CRITICAL 9.1
CVE-2019-5016

An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of…

Mitigation only
Fix from $2,300 2019-06-17
R8000 Firmware MEDIUM 5.3
CVE-2019-5017

An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of…

Mitigation only
Fix from $1,600 2019-06-17
Dgn2200 Firmware CRITICAL 9.8
CVE-2016-5649EPSS 27%

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_…

No fix yet
Fix from $2,300 2018-07-24
Wndr4500 Firmware HIGH 7.5
CVE-2016-5638

There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabi…

No fix yet
Fix from $1,950 2018-07-24
D6100 Firmware CRITICAL 9.8
CVE-2016-10174 KEVEPSS 83%

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buff…

Mitigation only
Fix from $2,300 2017-01-30
R6200 Firmware HIGH 8.1
CVE-2017-5521 KEVEPSS 89%

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 device…

Mitigation only
Fix from $1,950 2017-01-17
Readynas Surveillance HIGH 7.5
CVE-2016-5677EPSS 12%

NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622…

No fix yet
Fix from $1,950 2016-08-31
Readynas Surveillance HIGH 7.5
CVE-2016-5676EPSS 54%

cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows …

No fix yet
Fix from $1,950 2016-08-31
Readynas Surveillance CRITICAL 9.8
CVE-2016-5675EPSS 71%

handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR Read…

No fix yet
Fix from $2,300 2016-08-31
Readynas Surveillance CRITICAL 9.8
CVE-2016-5674EPSS 95%

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 thro…

No fix yet
Fix from $2,300 2016-08-31
Prosafe Network Management Software 300 HIGH 8.6
CVE-2016-1525EPSS 75%

Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users …

No fix yet
Fix from $1,950 2016-02-13
Wnr1000v3 Firmware HIGH 8.6
CVE-2015-8263

NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to s…

Mitigation only
Fix from $1,950 2015-12-27
Gs108pe Firmware HIGH 8.3
CVE-2014-2969

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote …

Mitigation only
Fix from $1,950 2014-07-07
Prosafe Fvs318n HIGH 7.5
CVE-2012-2439

The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attacker…

Mitigation only
Fix from $1,950 2012-04-28
Prosafe Wnap210 MEDIUM 6.8
CVE-2011-1674

The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visi…

Mitigation only
Fix from $1,600 2011-04-10
Prosafe Wnap210 MEDIUM 5.0
CVE-2011-1673

BackupConfig.php on the NetGear ProSafe WNAP210 allows remote attackers to obtain the administrator password by reading the configuration file.

Mitigation only
Fix from $1,600 2011-04-10
Wndap330 Firmware MEDIUM 5.5
CVE-2009-0052

The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR916…

No fix yet
Fix from $1,600 2009-11-12
Dg632 HIGH 7.8
CVE-2009-2256EPSS 7%

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an…

No fix yet
Fix from $1,950 2009-06-30
Dg632 HIGH 7.8
CVE-2009-2257EPSS 7%

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to…

No fix yet
Fix from $1,950 2009-06-30
Dg632 Firmware HIGH 7.8
CVE-2009-2258EPSS 7%

Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote atta…

No fix yet
Fix from $1,950 2009-06-30
Ssl312 HIGH 7.8
CVE-2009-0680EPSS 8%

cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted que…

No fix yet
Fix from $1,950 2009-02-22
Wgr614 HIGH 7.8
CVE-2008-6122

The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question …

No fix yet
Fix from $1,950 2009-02-11
Wg311v1 HIGH 7.5
CVE-2006-6125EPSS 14%

Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2006-11-27
Wg111v2 Driver HIGH 10.0
CVE-2006-5972EPSS 19%

Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802…

No fix yet
Fix from $1,950 2006-11-18