CVEs (154)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation.
This issue affects R7000P: through 1.3.3.154. |
1Netgear 2R6900p Firmware R7000p FirmwareMay 28, 2025 Dec 27, 2024 6.9 MEDIUM· v4 7.5 HIGH· v3 7.5 HIGH· v2 A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the arg...Show more |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST reque...Show more |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST reques...Show more |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
1Netgear 3R6400v2 Firmware R7000p FirmwareXr300 FirmwareMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Ser...Show more |
1Netgear 3R6400v2 Firmware R7000p FirmwareXr300 FirmwareMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Se...Show more |
1Netgear 3R6400v2 Firmware R7000p FirmwareXr300 FirmwareMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Serv...Show more |
1Netgear 3R6400v2 Firmware R7000p FirmwareXr300 FirmwareMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Servic...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreMay 21, 2025 Nov 5, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulner...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec par...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at bsw_pptp.cgi. This vulnerability allows attackers to caus...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to ca...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreMay 21, 2025 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to caus...Show more |
1Netgear 3R6400v2 Firmware R7000p FirmwareXr300 FirmwareMay 21, 2025 Nov 5, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execu...Show more |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the apn parameter at usbISP_detail_edit.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pppoe_localnetmask parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the l2tp_user_netmask parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
Netgear R7000P v1.3.3.154 was discovered to contain a command injection vulnerability via the device_name2 parameter at operation_mode.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a craft...Show more |