CVEs (48)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 31Ex3700 Firmware Ex3800 FirmwareEx6120 Firmware+28 moreJun 18, 2026 Jun 9, 2026 4.9 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. |
1Netgear 35Cbr750 Firmware Ex6120 FirmwareEx6130 Firmware+32 moreJun 18, 2026 Jun 9, 2026 4.3 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system. |
1Netgear 27Mr60 Firmware Mr70 FirmwareMr80 Firmware+24 moreJun 18, 2026 Jun 9, 2026 4.3 MEDIUM· v4 4.5 MEDIUM· v3 N/A· v2 Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity. |
1Netgear 19R7000 Firmware Rax20 FirmwareRax35v2 Firmware+16 moreJun 18, 2026 Jun 9, 2026 1.9 LOW· v4 4.5 MEDIUM· v3 N/A· v2 Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality. |
1Netgear 18Mr90 Firmware Ms90 FirmwareRax35v2 Firmware+15 moreJun 17, 2026 Dec 9, 2025 4.4 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipul...Show more |
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function. |
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function. |
NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function. |
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function. |
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function. |
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. |
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function. |
1Netgear 52D6220 Firmware D6400 FirmwareD7000v2 Firmware+49 moreJun 17, 2026 May 7, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected install...Show more |
1Netgear 52D6220 Firmware D6400 FirmwareD7000v2 Firmware+49 moreJun 17, 2026 May 7, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR...Show more |
NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affect...Show more |
1Netgear 33Cax80 Firmware Lax20 FirmwareMr60 Firmware+30 moreJun 17, 2026 Mar 29, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, th...Show more |
1Netgear 23Lax20 Firmware R6400 FirmwareR6700 Firmware+20 moreJun 17, 2026 Mar 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists w...Show more |
1Netgear 33Cax80 Firmware Lax20 FirmwareMr60 Firmware+30 moreJun 17, 2026 Mar 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The spec...Show more |
1Netgear 22Cbr40 Firmware Eax80 FirmwareEx7500 Firmware+19 moreJun 17, 2026 Dec 26, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.62, EX7500 before 1.0.0.72, R7900 before 1.0.4.38, R8000 before 1.0.4.68, RAX200 before 1.0.4.120, RBS40V before...Show more |
1Netgear 30Cbr40 Firmware Eax20 FirmwareEax80 Firmware+27 moreJun 17, 2026 Dec 26, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before 1...Show more |