Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

D6220 Firmware HIGH 8.8
CVE-2021-27239

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version …

Fix: 1.0.0.54 / 1.0.0.66+
Fix from $1,950 2021-03-29
Rbw30 Firmware CRITICAL 9.6
CVE-2021-29077

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, R…

Fix: 2.6.2.2 / 2.6.2.4+
Fix from $2,300 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29078

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29079

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Rbw30 Firmware HIGH 8.8
CVE-2021-29082

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBW30 before 2.6.1.4, RBS40V before 2.6.1.4, RBK752 before …

Fix: 2.6.1.4 / 3.2.15.25+
Fix from $1,950 2021-03-23
Rbw30 Firmware HIGH 8.4
CVE-2021-29081

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBK852 befor…

Fix: 2.6.2.2 / 3.2.17.12+
Fix from $1,950 2021-03-23
Rbk852 Firmware HIGH 8.1
CVE-2021-29080

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11,…

Fix: 1.0.11.116 / 1.3.2.126+
Fix from $1,950 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29066

Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Rbw30 Firmware CRITICAL 9.6
CVE-2021-29067

Certain NETGEAR devices are affected by authentication bypass. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK…

Fix: 2.6.2.2 / 2.6.2.4+
Fix from $2,300 2021-03-23
Rbk852 Firmware CRITICAL 9.6
CVE-2021-29076

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
Rbk852 Firmware CRITICAL 9.0
CVE-2021-29071

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RB…

Fix: 3.2.17.12+
Fix from $2,300 2021-03-23
R6700 Firmware HIGH 8.8
CVE-2021-29068

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7…

Fix: 1.0.1.62 / 1.0.2.16+
Fix from $1,950 2021-03-23
Xr450 Firmware HIGH 8.4
CVE-2021-29069

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR450 before 2.3.2.114, XR500 before 2.3.2.114, and …

Fix: 1.0.0.76 / 2.3.2.114+
Fix from $1,950 2021-03-23
Rbk852 Firmware HIGH 8.4
CVE-2021-29070

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RB…

Fix: 3.2.17.12+
Fix from $1,950 2021-03-23
Rbk852 Firmware HIGH 8.4
CVE-2021-29072

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RB…

Fix: 3.2.17.12+
Fix from $1,950 2021-03-23
R8000p Firmware HIGH 8.4
CVE-2021-29073

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R8000P before 1.4.1.66, MK62 before 1.0.…

Fix: 1.0.2.82 / 1.0.6.110+
Fix from $1,950 2021-03-23
Rbw30 Firmware HIGH 8.4
CVE-2021-29074

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.…

Fix: 2.6.2.2 / 3.2.17.12+
Fix from $1,950 2021-03-23
Rbw30 Firmware HIGH 8.4
CVE-2021-29075

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.…

Fix: 2.6.2.2 / 3.2.17.12+
Fix from $1,950 2021-03-23
Rbr850 Firmware CRITICAL 9.6
CVE-2021-29065

NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.

Fix: 3.2.10.11+
Fix from $2,300 2021-03-23
Gs116e Firmware HIGH 8.8
CVE-2020-35229

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can b…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware HIGH 8.8
CVE-2020-35231

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to by…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware HIGH 7.2
CVE-2020-35227

A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware HIGH 7.1
CVE-2020-35226

NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write re…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware MEDIUM 6.8
CVE-2020-35230

Multiple integer overflow parameters were found in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices. Most of the integer p…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware MEDIUM 6.5
CVE-2020-35233

The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device re…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware HIGH 8.8
CVE-2020-35223

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omittin…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware MEDIUM 6.8
CVE-2020-35225

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in w…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware MEDIUM 6.5
CVE-2020-35224

A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticat…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware HIGH 8.8
CVE-2020-35221

The hashing algorithm implemented for NSDP password authentication on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was found to be insecure, allowing …

Mitigation only
Fix from $1,950 2021-03-10
Br200 Firmware HIGH 8.8
CVE-2021-27254

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not requi…

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,950 2021-03-05