Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

R8500 Firmware MEDIUM 5.7
CVE-2024-51006

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability …

Mitigation only
Fix from $1,600 2024-11-05
Xr300 Firmware MEDIUM 5.7
CVE-2024-51007

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers …

Mitigation only
Fix from $1,600 2024-11-05
Xr300 Firmware MEDIUM 5.7
CVE-2024-51011

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppo…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware HIGH 8.0
CVE-2024-50993

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnera…

Mitigation only
Fix from $1,950 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50994

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50995

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allow…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50996

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server p…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50997

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip…

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50998

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port …

Mitigation only
Fix from $1,600 2024-11-05
R8500 Firmware MEDIUM 5.7
CVE-2024-50999

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerabilit…

Mitigation only
Fix from $1,600 2024-11-05
Ex6120 Firmware MEDIUM 6.8
CVE-2024-35518

Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

Fix: after 1.0.0.68
Fix from $1,600 2024-10-14
Ex3700 Firmware MEDIUM 6.8
CVE-2024-35519

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap…

Fix: after 1.0.2.28
Fix from $1,600 2024-10-14
R7000 Firmware MEDIUM 6.8
CVE-2024-35520EPSS 9%

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Mitigation only
Fix from $1,600 2024-10-14
Ex3700 Firmware HIGH 7.2
CVE-2024-35522

Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via t…

Fix: 1.0.0.98+
Fix from $1,950 2024-10-11
Xr1000 Firmware HIGH 7.2
CVE-2024-35517EPSS 15%

Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

Mitigation only
Fix from $1,950 2024-10-11
Dgn1000ww Firmware HIGH 8.8
CVE-2024-42756EPSS 14%

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

Mitigation only
Fix from $1,950 2024-08-23
Prosafe Network Management System HIGH 8.8
CVE-2024-6813

NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

Mitigation only
Fix from $1,950 2024-08-21
Prosafe Network Management System HIGH 8.8
CVE-2024-6814

NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke…

Mitigation only
Fix from $1,950 2024-08-21
Wnr614 Firmware HIGH 8.8
CVE-2024-36787

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspe…

No fix yet
Fix from $1,950 2024-06-07
Wnr614 Firmware HIGH 8.8
CVE-2024-36790

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

No fix yet
Fix from $1,950 2024-06-07
Wnr614 Firmware HIGH 8.2
CVE-2024-36792

An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.

No fix yet
Fix from $1,950 2024-06-07
Wnr614 Firmware HIGH 8.1
CVE-2024-36789

An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.

No fix yet
Fix from $1,950 2024-06-07
Prosafe Network Management System HIGH 8.8
CVE-2024-5505EPSS 47%

NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote att…

Fix: 1.7.0.37+
Fix from $1,950 2024-06-06
Prosafe Network Management Software 300 HIGH 8.8
CVE-2024-5246EPSS 31%

NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2024-05-23
Prosafe Network Management System HIGH 8.8
CVE-2024-5247EPSS 27%

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot…

Fix: 1.7.0.37+
Fix from $1,950 2024-05-23
Prosafe Network Management System HIGH 7.8
CVE-2024-5245

NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to …

Fix: 1.7.0.37+
Fix from $1,950 2024-05-23
Cax30 Firmware HIGH 8.8
CVE-2022-43654

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary c…

Fix: 2.1.3.10+
Fix from $1,950 2024-05-07
Dc112a Firmware HIGH 8.8
CVE-2021-34982

NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …

Fix: 1.0.0.46 / 1.0.0.62+
Fix from $1,950 2024-05-07
Xr1000 Firmware MEDIUM 6.5
CVE-2021-34983

NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-a…

Fix: 1.0.0.62 / 1.0.0.64+
Fix from $1,600 2024-05-07
D7800 Firmware HIGH 8.8
CVE-2021-34947

NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitr…

Fix: 1.0.0.146 / 1.0.1.64+
Fix from $1,950 2024-05-07