Netgear
netgear
1,334 CVEs • 1,110 products
Products (1,110)
Click to collapseToggle
Products (1,110)
Click to collapse
CVEs (1,334)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 8D7800 Firmware R7500 FirmwareR7800 Firmware+5 moreJun 17, 2026 Apr 15, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2...Show more |
1Netgear 8D7800 Firmware R7500 FirmwareR7800 Firmware+5 moreJun 17, 2026 Apr 15, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, XR500 before 2...Show more |
1Netgear 26D6220 Firmware D6400 FirmwareD7000 Firmware+23 moreJun 17, 2026 Apr 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, R6220 before 1.1.0.80, R6250...Show more |
1Netgear 16D7800 Firmware R7500 FirmwareR7800 Firmware+13 moreJun 17, 2026 Apr 15, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2...Show more |
1Netgear 17D7800 Firmware R7500 FirmwareR7800 Firmware+14 moreJun 17, 2026 Apr 15, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by Stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2...Show more |
1Netgear 10D3600 Firmware D6000 FirmwareD6100 Firmware+7 moreJun 17, 2026 Apr 15, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.60, D3600 before 1.0.0.75, D6000 before 1.0.0.75, R9000 before 1.0.4.26, R8900 before 1.0.4....Show more |
1Netgear 5Wc7500 Firmware Wc7520 FirmwareWc7600v1 Firmware+2 moreNov 21, 2024 Apr 1, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running fir...Show more |
1Netgear 3Prosafe Wc7520 Firmware Prosafe Wc7600 FirmwareProsafe Wc9500 FirmwareNov 21, 2024 Mar 23, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php. |
On NETGEAR GS728TPS devices through 5.3.0.35, a remote attacker having network connectivity to the web-administration panel can access part of the web panel, bypassing authentication. |
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an e...Show more |
1Netgear 1Cg3700b Firmware Jun 17, 2026 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP. |
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic Authentication or an a...Show more |
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device...Show more |
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands...Show more |
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demo...Show more |
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI l...Show more |
1Netgear 1Nighthawk X10 R9000 Firmware Jun 17, 2026 Feb 24, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname field, an attacker may execute stored XSS attacks against this device. When the malicious DHCP request i...Show more |
1Netgear 1Nighthawk X10 R9000 Firmware Jun 17, 2026 Feb 24, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by supplying a malicious X-Forwarded-For header while performing an incorrect login attempt. The value suppl...Show more |
1Netgear 1Nighthawk X10 R9000 Firmware Jun 17, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwid...Show more |
1Netgear 1Nighthawk X10 R9000 Firmware Jun 17, 2026 Feb 24, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device...Show more |