Netgear
netgear
1,334 CVEs • 1,110 products
Products (1,110)
Click to collapseToggle
Products (1,110)
Click to collapse
CVEs (1,334)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information. |
1Netgear 1Ac1200 R6220 Firmware Jun 17, 2026 Feb 10, 2020 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not required to exploit this...Show more |
1Netgear 2Wgr614v7 Firmware Wgr614v9 FirmwareNov 21, 2024 Feb 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/W...Show more |
1Netgear 2Wgr614v7 Firmware Wgr614v9 FirmwareNov 21, 2024 Feb 6, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002. |
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. |
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". |
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash). |
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. |
4Compal NetgearSagemcom+1 more77284e Firmware 7486e FirmwareC6250emr Firmware+4 moreJun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of...Show more |
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no...Show more |
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN. |
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34. |
1Netgear 2Wnr3500l Firmware Wnr3500u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens. |
1Netgear 2Wnr3500l Firmware Wnr3500u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L. |
1Netgear 2Wnr3500l Firmware Wnr3500u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service. |
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS. |
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter. |
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case. |
1Netgear 10Dgn2200 Firmware Dgn2200m FirmwareDgnd3700 Firmware+7 moreJun 17, 2026 Oct 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, W...Show more |
1Netgear 33Ac1450 Firmware D8500 FirmwareDc112a Firmware+30 moreJun 17, 2026 Oct 9, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a va...Show more |