← Back

Wac104 Firmware

wac104_firmware

Vendor: Netgear • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
3Mbr1517 Firmware
Wac104 FirmwareWnce3001 Firmware
Jun 17, 2026
Mar 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key informatio...Show more
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.Show less
1Netgear
5R6220 Firmware
R6900 FirmwareR7450 Firmware+2 more
Jun 17, 2026
Mar 17, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version i...Show more
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device.Show less
1Netgear
1Wac104 Firmware
Jun 17, 2026
Aug 11, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.
1Netgear
1Wac104 Firmware
Jun 17, 2026
Jun 30, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring...Show more
NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).Show less
1Netgear
1Wac104 Firmware
Jun 17, 2026
Dec 30, 2020
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
NETGEAR WAC104 devices before 1.0.4.13 are affected by a buffer overflow by an authenticated user.