Vulnerability index

Browse CVEs

287 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2021-45732 Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipu… R6700 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 7.5 CVE-2021-45077 Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services… R6700 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 8.8 CVE-2021-20166 Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router container… Rax43 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 8.8 CVE-2021-20170 Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configu… Rax43 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 8.8 CVE-2021-20173 Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system up… R6700 Firmware No fix yet Fix from $1,9502021-12-30 HIGH 8.0 CVE-2021-20167EPSS 8% Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the n… Rax43 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 7.8 CVE-2021-20172 All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of… Genie Installer No fix yet Fix from $1,9502021-12-30 HIGH 7.5 CVE-2021-20174 Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from t… R6700 Firmware Mitigation only Fix from $1,9502021-12-30 HIGH 7.5 CVE-2021-20175 Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from … R6700 Firmware Mitigation only Fix from $1,9502021-12-30 MEDIUM 6.8 CVE-2021-20168 Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is ab… Rax43 Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 6.8 CVE-2021-20169 Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent … Rax43 Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 6.8 CVE-2021-23147 Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the de… R6700 Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 5.5 CVE-2021-20171 Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored… Rax43 Firmware Mitigation only Fix from $1,6002021-12-30 HIGH 8.1 CVE-2021-40847EPSS 10% The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root… R6400v2 Firmware No fix yet Fix from $1,9502021-09-21 HIGH 7.2 CVE-2021-41383 setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field. R6020 Firmware No fix yet Fix from $1,9502021-09-17 CRITICAL 9.8 CVE-2021-27274EPSS 8% This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… Prosafe Network Management System Mitigation only Fix from $2,3002021-03-29 HIGH 8.8 CVE-2021-27273EPSS 65% This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… Prosafe Network Management System Mitigation only Fix from $1,9502021-03-29 HIGH 8.3 CVE-2021-27275EPSS 73% This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE … Prosafe Network Management System Mitigation only Fix from $1,9502021-03-29 HIGH 7.1 CVE-2021-27272EPSS 74% This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… Prosafe Network Management System Mitigation only Fix from $1,9502021-03-29 HIGH 7.1 CVE-2021-27276EPSS 72% This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… Prosafe Network Management System Mitigation only Fix from $1,9502021-03-29 HIGH 8.8 CVE-2020-35229 The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can b… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 HIGH 8.8 CVE-2020-35231 The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to by… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 HIGH 7.2 CVE-2020-35227 A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 HIGH 7.1 CVE-2020-35226 NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write re… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 MEDIUM 6.8 CVE-2020-35230 Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer p… Gs116e Firmware Mitigation only Fix from $1,6002021-03-10 MEDIUM 6.5 CVE-2020-35233 The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device re… Gs116e Firmware Mitigation only Fix from $1,6002021-03-10 HIGH 8.8 CVE-2020-35223 The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omittin… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 MEDIUM 6.8 CVE-2020-35225 The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in w… Gs116e Firmware Mitigation only Fix from $1,6002021-03-10 MEDIUM 6.5 CVE-2020-35224 A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticat… Gs116e Firmware Mitigation only Fix from $1,6002021-03-10 HIGH 8.8 CVE-2020-35221 The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing … Gs116e Firmware Mitigation only Fix from $1,9502021-03-10