Vulnerability index

Browse CVEs

1,134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cax30 Firmware HIGH 8.8
CVE-2026-9211

An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.

Fix: 1.0.5.34 / 1.0.10.72+
Fix from $1,950 2026-06-09
Mr70 Firmware HIGH 8.1
CVE-2026-9213

A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and …

Fix: 1.0.2.86 / 1.0.4.48+
Fix from $1,950 2026-06-09
Lbr1020 Firmware HIGH 8.0
CVE-2026-9212

Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impactin…

Fix: 1.0.4.96 / 1.0.5.50+
Fix from $1,950 2026-06-09
Rbe970 Firmware MEDIUM 6.5
CVE-2026-3088

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

Fix: 7.2.7.15 / 9.10.1.4+
Fix from $1,600 2026-06-09
Jr6150 Firmware HIGH 8.0
CVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local W…

Mitigation only
Fix from $1,950 2026-06-09
Rax120 Firmware MEDIUM 5.9
CVE-2026-0420

An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perf…

Fix: 1.0.6.106 / 1.2.9.52+
Fix from $1,600 2026-06-09
Rbe970 Firmware HIGH 8.0
CVE-2026-0411

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain admi…

Fix: 4.4.2.2 / 6.3.8.11+
Fix from $1,950 2026-06-09
Rbe370 Firmware MEDIUM 6.4
CVE-2026-0409

A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run co…

Fix: 12.1.2.7+
Fix from $1,600 2026-06-09
Rbr20 Firmware HIGH 7.7
CVE-2022-40620

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading u…

Fix: 1.0.5.42 / 1.0.11.134+
Fix from $1,950 2026-01-28
Rbr20 Firmware HIGH 7.7
CVE-2022-40619

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devi…

Fix: 1.0.5.42 / 1.0.11.134+
Fix from $1,950 2026-01-28
Ex2800 Firmware HIGH 8.0
CVE-2026-0408

A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the …

Fix: 1.0.1.82+
Fix from $1,950 2026-01-13
Rbe971 Firmware HIGH 8.0
CVE-2026-0403

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injecti…

Fix: 7.2.8.5 / 9.10.0.2+
Fix from $1,950 2026-01-13
Rbr750 Firmware HIGH 8.0
CVE-2026-0404

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over W…

Fix: 7.2.8.5+
Fix from $1,950 2026-01-13
Xr1000v2 Firmware HIGH 8.0
CVE-2026-0406

An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injecti…

Fix: 1.1.2.34+
Fix from $1,950 2026-01-13
Ex5000 Firmware HIGH 8.0
CVE-2026-0407

An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physi…

Fix: 1.0.1.82+
Fix from $1,950 2026-01-13
Cbr750 Firmware HIGH 7.8
CVE-2026-0405

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an…

Fix: 4.6.14.8 / 4.6.15.14+
Fix from $1,950 2026-01-13
Ex8000 Firmware CRITICAL 9.8
CVE-2025-50526

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

Mitigation only
Fix from $2,300 2025-12-23
Ex8000 Firmware MEDIUM 6.5
CVE-2025-45493

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.

Mitigation only
Fix from $1,600 2025-12-23
Rs700 Firmware HIGH 7.5
CVE-2025-12946

A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the route…

Fix: 1.0.9.6 / 1.0.17.142+
Fix from $1,950 2025-12-09
R7000p Firmware HIGH 7.2
CVE-2025-12945

A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. T…

Fix: after 1.3.3.154
Fix from $1,950 2025-12-09
C6230 Firmware MEDIUM 5.7
CVE-2025-12941

Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users r…

Mitigation only
Fix from $1,600 2025-12-09
Dgn2200 Firmware HIGH 8.8
CVE-2025-12944

Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to poten…

Fix: 1.0.0.132+
Fix from $1,950 2025-11-11
R6260 Firmware HIGH 7.5
CVE-2025-12942

Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform …

Fix: 1.1.0.86+
Fix from $1,950 2025-11-11
Rax30 Firmware HIGH 7.5
CVE-2025-12943

Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE780…

Fix: 1.0.9.82 / 1.0.14.108+
Fix from $1,950 2025-11-11
Wax610y Firmware MEDIUM 5.5
CVE-2025-12940

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig I…

Fix: 11.8.0.10+
Fix from $1,600 2025-11-11
Dgn2200b Firmware HIGH 7.2
CVE-2013-10060

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via…

Fix: after 1.1.0.36
Fix from $1,950 2025-08-01
Dgn1000b Firmware HIGH 7.2
CVE-2013-10061

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45…

No fix yet
Fix from $1,950 2025-08-01
Rax30 Firmware HIGH 7.5
CVE-2025-44652

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when…

Mitigation only
Fix from $1,950 2025-07-21
Rax30 Firmware CRITICAL 9.8
CVE-2025-44658

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensio…

Mitigation only
Fix from $2,300 2025-07-21
R7000 Firmware HIGH 7.5
CVE-2025-44650

In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can …

Mitigation only
Fix from $1,950 2025-07-21