Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

D6100 Firmware CRITICAL 9.8
CVE-2016-10174 KEVEPSS 83%

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buff…

Mitigation only
Fix from $2,300 2017-01-30
Wnr2000v5 Firmware CRITICAL 9.8
CVE-2016-10175EPSS 65%

The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user…

Fix: after 1.0.0.34
Fix from $2,300 2017-01-30
Wnr2000v5 Firmware CRITICAL 9.8
CVE-2016-10176EPSS 78%

The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This…

Fix: after 1.0.0.34
Fix from $2,300 2017-01-30
R6200 Firmware HIGH 8.1
CVE-2017-5521 KEVEPSS 89%

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 device…

Mitigation only
Fix from $1,950 2017-01-17
Arlo Base Station Firmware CRITICAL 9.8
CVE-2016-10115EPSS 5%

NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fi…

Fix: after 1.8.1_6094
Fix from $2,300 2017-01-04
Arlo Base Station Firmware HIGH 8.1
CVE-2016-10116

NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fi…

Fix: after 1.8.1_6094
Fix from $1,950 2017-01-04
Fvs336gv3 Firmware MEDIUM 6.5
CVE-2016-10106

Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8…

Fix: after 4.3-3.6
Fix from $1,600 2017-01-03
D6220 Firmware HIGH 8.8
CVE-2016-6277 KEVEPSS 100%

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.…

Fix: after 1.0.7.2_1.1.93
Fix from $1,950 2016-12-14
Readynas Surveillance HIGH 7.5
CVE-2016-5677EPSS 12%

NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622…

No fix yet
Fix from $1,950 2016-08-31
Readynas Surveillance HIGH 7.5
CVE-2016-5676EPSS 54%

cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows …

No fix yet
Fix from $1,950 2016-08-31
Readynas Surveillance CRITICAL 9.8
CVE-2016-5675EPSS 71%

handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR Read…

No fix yet
Fix from $2,300 2016-08-31
Readynas Surveillance CRITICAL 9.8
CVE-2016-5674EPSS 95%

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 thro…

No fix yet
Fix from $2,300 2016-08-31
D3600 Firmware HIGH 7.5
CVE-2015-8289

The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote atta…

Fix: after 1.0.0.49
Fix from $1,950 2016-06-20
D3600 Firmware MEDIUM 5.9
CVE-2015-8288

NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different…

Fix: after 1.0.0.49
Fix from $1,600 2016-06-20
Prosafe Network Management Software 300 HIGH 8.6
CVE-2016-1525EPSS 75%

Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users …

No fix yet
Fix from $1,950 2016-02-13
Prosafe Network Management Software 300 CRITICAL 9.6
CVE-2016-1524EPSS 94%

Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrar…

Fix: after 1.5.0.11
Fix from $2,300 2016-02-13
Wnr1000v3 Firmware HIGH 8.6
CVE-2015-8263

NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to s…

Mitigation only
Fix from $1,950 2015-12-27
Gs108pe Firmware HIGH 8.3
CVE-2014-2969

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote …

Mitigation only
Fix from $1,950 2014-07-07
Prosafe Firmware HIGH 7.8
CVE-2013-4776EPSS 7%

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a d…

Fix: after 5.4.1.13
Fix from $1,950 2013-12-19
Prosafe Firmware HIGH 7.8
CVE-2013-4775EPSS 15%

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, G…

Fix: after 5.4.1.14
Fix from $1,950 2013-12-19
Raidiator HIGH 10.0
CVE-2013-2751EPSS 72%

Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x befo…

Fix: 4.1.12 / 4.2.24+
Fix from $1,950 2013-12-12
Raidiator MEDIUM 6.8
CVE-2013-2752

Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 al…

Fix: 4.1.12 / 4.2.24+
Fix from $1,600 2013-12-12
Prosafe Fvs318n HIGH 7.5
CVE-2012-2439

The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attacker…

Mitigation only
Fix from $1,950 2012-04-28
Prosafe Wnap210 MEDIUM 6.8
CVE-2011-1674

The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visi…

Mitigation only
Fix from $1,600 2011-04-10
Prosafe Wnap210 MEDIUM 5.0
CVE-2011-1673

BackupConfig.php on the NetGear ProSafe WNAP210 allows remote attackers to obtain the administrator password by reading the configuration file.

Mitigation only
Fix from $1,600 2011-04-10
Wndap330 Firmware MEDIUM 5.5
CVE-2009-0052

The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR916…

No fix yet
Fix from $1,600 2009-11-12
Dg632 HIGH 7.8
CVE-2009-2256EPSS 7%

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an…

No fix yet
Fix from $1,950 2009-06-30
Dg632 HIGH 7.8
CVE-2009-2257EPSS 7%

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to…

No fix yet
Fix from $1,950 2009-06-30
Dg632 Firmware HIGH 7.8
CVE-2009-2258EPSS 7%

Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote atta…

No fix yet
Fix from $1,950 2009-06-30
Ssl312 HIGH 7.8
CVE-2009-0680EPSS 8%

cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted que…

No fix yet
Fix from $1,950 2009-02-22