Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wndr4700 Firmware HIGH 7.5
CVE-2013-3070

An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK…

Patch available
Fix from $1,950 2019-11-14
Wndr4700 Firmware CRITICAL 9.8
CVE-2013-3073

A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

Patch available
Fix from $2,300 2019-11-14
Wnr3500u Firmware MEDIUM 6.5
CVE-2013-3516

NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF toke…

No fix yet
Fix from $1,600 2019-11-13
Wnr3500u Firmware MEDIUM 5.4
CVE-2013-3517

Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.

No fix yet
Fix from $1,600 2019-11-13
Wnr3500u Firmware CRITICAL 9.8
CVE-2013-4657

Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.

Mitigation only
Fix from $2,300 2019-11-13
Jnr1010 Firmware CRITICAL 9.8
CVE-2016-11014

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

Fix: 1.0.0.32+
Fix from $2,300 2019-10-16
Jnr1010 Firmware MEDIUM 6.5
CVE-2016-11015

NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.

Fix: 1.0.0.32+
Fix from $1,600 2019-10-16
Jnr1010 Firmware MEDIUM 6.1
CVE-2016-11016

NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.

Fix: 1.0.0.32+
Fix from $1,600 2019-10-16
Mbr1515 Firmware CRITICAL 9.8
CVE-2019-17373

Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg …

Mitigation only
Fix from $2,300 2019-10-09
Ac1450 Firmware HIGH 8.1
CVE-2019-17372

Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can th…

No fix yet
Fix from $1,950 2019-10-09
Srx5308 Firmware HIGH 7.5
CVE-2019-17049

NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user account.

No fix yet
Fix from $1,950 2019-09-30
Wnr2000 Firmware HIGH 7.5
CVE-2019-5054

An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0…

No fix yet
Fix from $1,950 2019-09-11
Wnr2000 Firmware HIGH 7.5
CVE-2019-5055

An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version …

No fix yet
Fix from $1,950 2019-09-11
Mr1100 Firmware CRITICAL 9.8
CVE-2019-14527

An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authe…

Fix: 12.06.03+
Fix from $2,300 2019-08-14
Mr1100 Firmware HIGH 8.1
CVE-2019-14526

An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a d…

Fix: 12.06.03+
Fix from $1,950 2019-08-14
Ex7000 Firmware MEDIUM 5.2
CVE-2016-10864

NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.

Fix: after 1.0.0.42_1.0.94
Fix from $1,600 2019-08-08
Wndr3400v3 Firmware CRITICAL 9.8
CVE-2019-14363

A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to r…

Fix: after 1.0.1.24
Fix from $2,300 2019-07-28
R8000 Firmware CRITICAL 9.1
CVE-2019-5016

An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of…

Mitigation only
Fix from $2,300 2019-06-17
R8000 Firmware MEDIUM 5.3
CVE-2019-5017

An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of…

Mitigation only
Fix from $1,600 2019-06-17
Readynas Surveillance Firmware CRITICAL 9.8
CVE-2017-18378EPSS 8%

In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp…

Fix: 1.1.4-7 / 1.4.3-17+
Fix from $2,300 2019-06-11
Insight HIGH 7.6
CVE-2019-12591

NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.

Fix: 5.6+
Fix from $1,950 2019-06-03
Dgn2200 Firmware CRITICAL 9.8
CVE-2016-5649EPSS 27%

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_…

No fix yet
Fix from $2,300 2018-07-24
Wndr4500 Firmware HIGH 7.5
CVE-2016-5638

There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabi…

No fix yet
Fix from $1,950 2018-07-24
Wnr2000 Firmware CRITICAL 9.8
CVE-2017-6862 KEVEPSS 43%

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and r…

Fix: 1.0.0.42 / 1.0.0.66+
Fix from $2,300 2017-05-26
Wnap320 Firmware CRITICAL 9.8
CVE-2016-1555 KEVEPSS 98%

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802…

Fix: after 3.3.2
Fix from $2,300 2017-04-21
Wnap320 Firmware CRITICAL 9.8
CVE-2016-1557

Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.

Fix: after 3.0.5.0
Fix from $2,300 2017-04-21
Wnap320 Firmware HIGH 7.5
CVE-2016-1556

Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote…

Fix: after 3.3.2
Fix from $1,950 2017-04-21
Dgn2200 Firmware HIGH 8.8
CVE-2017-6366

Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijac…

Fix: after 10.0.0.50
Fix from $1,950 2017-03-15
Dgn2200 Series Firmware HIGH 8.8
CVE-2017-6334 KEVEPSS 72%

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell…

Fix: after 10.0.0.50
Fix from $1,950 2017-03-06
Dgn2200 Firmware CRITICAL 9.8
CVE-2017-6077 KEVEPSS 68%

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell meta…

Fix: after 10.0.0.50
Fix from $2,300 2017-02-22