← Back

Netgear

netgear

1,334 CVEs • 1,110 products

Products (1,110)

Click to collapse
Toggle
Mr60 Firmware
mr60_firmware
Ms60 Firmware
ms60_firmware

CVEs (1,334)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
1Cg3100 Firmware
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.3 CRITICAL· v3
4.3 MEDIUM· v2
A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.
1Netgear
1Ac1200 R6220 Firmware
Jun 17, 2026
Feb 10, 2020
N/A· v4
9.4 CRITICAL· v3
7.5 HIGH· v2
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not required to exploit this...Show more
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of path strings. By inserting a null byte into the path, the user can skip most authentication checks. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-8616.Show less
1Netgear
2Wgr614v7 Firmware
Wgr614v9 Firmware
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/W...Show more
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than CVE-2012-6340.Show less
1Netgear
2Wgr614v7 Firmware
Wgr614v9 Firmware
Nov 21, 2024
Feb 6, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.
1Netgear
1Wnr1000 Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
1Netgear
1Wnr1000 Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
4Compal
NetgearSagemcom+1 more
77284e Firmware
7486e FirmwareC6250emr Firmware+4 more
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of...Show more
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.Show less
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no...Show more
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.Show less
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Nov 14, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
1Netgear
2Wnr3500l Firmware
Wnr3500u Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
1Netgear
2Wnr3500l Firmware
Wnr3500u Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
1Netgear
2Wnr3500l Firmware
Wnr3500u Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
1Netgear
1Jnr1010 Firmware
Nov 21, 2024
Oct 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
1Netgear
1Jnr1010 Firmware
Nov 21, 2024
Oct 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
1Netgear
1Jnr1010 Firmware
Nov 21, 2024
Oct 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
1Netgear
10Dgn2200 Firmware
Dgn2200m FirmwareDgnd3700 Firmware+7 more
Jun 17, 2026
Oct 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, W...Show more
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.Show less
1Netgear
33Ac1450 Firmware
D8500 FirmwareDc112a Firmware+30 more
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a va...Show more
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.Show less