Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-11788 Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.68, PR2000 before 1.0.0.28, R6… D6200 Firmware 1.0.0.28 / 1.0.0.46+ Fix from $1,9502020-04-15 HIGH 8.0 CVE-2019-20642 NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass. Rax40 Firmware 1.0.3.64+ Fix from $1,9502020-04-15 HIGH 7.5 CVE-2019-20643 NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information. Rax40 Firmware 1.0.3.64+ Fix from $1,9502020-04-15 HIGH 7.5 CVE-2019-20649 NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information. Mr1100 Firmware 12.06.08.00+ Fix from $1,9502020-04-15 HIGH 7.5 CVE-2019-20650 Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR500 before 2.3.2.56, and XR700 … R8900 Firmware 1.0.1.20 / 1.0.5.2+ Fix from $1,9502020-04-15 MEDIUM 5.7 CVE-2019-20647 NETGEAR RAX40 devices before 1.0.3.64 are affected by denial of service. Rax40 Firmware 1.0.3.64+ Fix from $1,6002020-04-15 MEDIUM 6.5 CVE-2019-20638 NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials. Mr1100 Firmware 12.06.08.00+ Fix from $1,6002020-04-15 HIGH 8.8 CVE-2020-11770 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v… D6220 Firmware 1.0.0.52 / 1.0.0.86+ Fix from $1,9502020-04-15 HIGH 7.2 CVE-2019-20767 Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.60, D3600 before 1.0.… D6100 Firmware 1.0.0.58 / 1.0.0.60+ Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2018-11106 NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: … Wc7500 Firmware 2.5.0.46 / 6.5.3.5+ Fix from $2,3002020-04-01 HIGH 7.2 CVE-2016-11022 NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell … Prosafe Wc9500 Firmware No fix yet Fix from $1,9502020-03-23 CRITICAL 9.8 CVE-2019-13394 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP. Cg3700b Firmware No fix yet Fix from $2,3002020-03-13 HIGH 8.8 CVE-2019-13395 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA… Cg3700b Firmware No fix yet Fix from $1,9502020-03-13 HIGH 7.5 CVE-2019-13393 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre… Cg3700b Firmware No fix yet Fix from $1,9502020-03-13 CRITICAL 9.8 CVE-2019-20488 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to com… Wnr1000 Firmware No fix yet Fix from $2,3002020-03-02 CRITICAL 9.8 CVE-2019-20489 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other proble… Wnr1000 Firmware Mitigation only Fix from $2,3002020-03-02 HIGH 8.8 CVE-2019-20487 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unau… Wnr1000 Firmware Mitigation only Fix from $1,9502020-03-02 MEDIUM 6.1 CVE-2019-20486 An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vul… Wnr1000 Firmware No fix yet Fix from $1,6002020-03-02 CRITICAL 9.8 CVE-2019-12511 In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC addres… Nighthawk X10 R9000 Firmware 1.0.4.26+ Fix from $2,3002020-02-24 CRITICAL 9.1 CVE-2019-12510 In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/se… Nighthawk X10 R9000 Firmware 1.0.4.26+ Fix from $2,3002020-02-24 MEDIUM 6.1 CVE-2019-12512 In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by supplying a malicious X-Forwarded-… Nighthawk X10 R9000 Firmware 1.0.4.24+ Fix from $1,6002020-02-24 MEDIUM 6.1 CVE-2019-12513 In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname field, an attacker may execute st… Nighthawk X10 R9000 Firmware 1.0.4.24+ Fix from $1,6002020-02-24 CRITICAL 9.3 CVE-2014-3919 A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a… Cg3100 Firmware 3.9.2421.13.mp3.v0027+ Fix from $2,3002020-02-13 CRITICAL 9.4 CVE-2019-17137 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.… Ac1200 R6220 Firmware Mitigation only Fix from $2,3002020-02-10 MEDIUM 6.5 CVE-2012-6341 An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previo… Wgr614v9 Firmware No fix yet Fix from $1,6002020-02-06 CRITICAL 9.8 CVE-2013-3316 Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". Wnr1000 Firmware 1.0.2.60+ Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-3317 Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. Wnr1000 Firmware 1.0.2.60+ Fix from $2,3002020-01-29 CRITICAL 9.8 CVE-2013-3071 NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. Wndr4700 Firmware No fix yet Fix from $2,3002020-01-28 HIGH 7.5 CVE-2013-3074 NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash). Wndr4700 Firmware No fix yet Fix from $1,9502020-01-28 CRITICAL 9.8 CVE-2013-3072 An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that w… Wndr4700 Firmware No fix yet Fix from $2,3002019-11-14