Netgear
netgear
1,334 CVEs • 1,110 products
Products (1,110)
Click to collapseToggle
Products (1,110)
Click to collapse
CVEs (1,334)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request. |
1Netgear 1Wnr2000v5 Firmware May 13, 2026 Jan 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and process...Show more |
1Netgear 1Wnr2000v5 Firmware May 13, 2026 Jan 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combin...Show more |
1Netgear 28D6100 Firmware D7000 FirmwareD7800 Firmware+25 moreApr 21, 2026 Jan 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve...Show more |
1Netgear 13Ac1450 Firmware D6220 FirmwareD6300 Firmware+10 moreApr 21, 2026 Jan 17, 2017 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to...Show more |
1Netgear 3Arlo Base Station Firmware Arlo Q Camera FirmwareArlo Q Plus Camera FirmwareMay 6, 2026 Jan 4, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and thr...Show more |
1Netgear 3Arlo Base Station Firmware Arlo Q Camera FirmwareArlo Q Plus Camera FirmwareMay 6, 2026 Jan 4, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, whic...Show more |
1Netgear 4Fvs318gv2 Firmware Fvs318n FirmwareFvs336gv3 Firmware+1 moreMay 6, 2026 Jan 3, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (do...Show more |
1Netgear 11D6220 Firmware D6400 FirmwareR6250 Firmware+8 moreApr 21, 2026 Dec 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 b...Show more |
2Netgear Nuuo2Nvrmini 2 Readynas SurveillanceMay 6, 2026 Aug 31, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transf...Show more |
2Netgear Nuuo2Nvrmini 2 Readynas SurveillanceMay 6, 2026 Aug 31, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_...Show more |
2Netgear Nuuo3Nvrmini 2 NvrsoloReadynas SurveillanceMay 6, 2026 Aug 31, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to...Show more |
2Netgear Nuuo3Nvrmini 2 NvrsoloReadynas SurveillanceMay 6, 2026 Aug 31, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefc...Show more |
2Netgear Nuuo4Crystal Nvrmini 2Nvrsolo+1 moreMay 6, 2026 Aug 31, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execut...Show more |
2Netgear Nuuo3Nvrmini 2 NvrsoloReadynas SurveillanceMay 6, 2026 Aug 31, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the...Show more |
1Netgear 2D3600 Firmware D6000 FirmwareMay 6, 2026 Jun 20, 2016 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the c...Show more |
1Netgear 2D3600 Firmware D6000 FirmwareMay 6, 2026 Jun 20, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryp...Show more |
5Dell NetgearSamsung+2 more5Emc Powerscale Onefs Gs1900 10hp FirmwareJr6150 Firmware+2 moreMay 6, 2026 Apr 6, 2016 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets,...Show more |
4Dell NetgearZyxel+1 more4Emc Powerscale Onefs Gs1900 10hp FirmwareJr6150 Firmware+1 moreMay 6, 2026 Apr 6, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malforme...Show more |
7Cisco IntelNetgear+4 more7Core I5 9400f Firmware Gs1900 10hp FirmwareIos Xe+4 moreMay 6, 2026 Mar 26, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Insta...Show more |