CVEs (127)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 31Ex3700 Firmware Ex3800 FirmwareEx6120 Firmware+28 moreJun 18, 2026 Jun 9, 2026 4.9 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. |
1Netgear 27Mr60 Firmware Mr70 FirmwareMr80 Firmware+24 moreJun 18, 2026 Jun 9, 2026 4.3 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity. |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulner...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted reques...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted requ...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec par...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at bsw_pptp.cgi. This vulnerability allows attackers to caus...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to ca...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to caus...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_pri_dns parameter at ipv6_fix.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component ap_mode.cgi via the apmode_gateway parameter. This vulner...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. |
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a craf...Show more |
1Netgear 2R7000p Firmware R8500 FirmwareJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec par...Show more |
1Netgear 4R6400v2 Firmware R7000p FirmwareR8500 Firmware+1 moreJun 17, 2026 Nov 5, 2024 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a...Show more |
Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |
Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cau...Show more |