Filtered by vendor Netgear
Subscribe
Total
1346 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-3088 | 1 Netgear | 16 Rbe970, Rbe970 Firmware, Rbe971 and 13 more | 2026-07-23 | N/A | 6.5 MEDIUM |
| Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests. | |||||
| CVE-2026-0409 | 1 Netgear | 8 Rbe370, Rbe370 Firmware, Rbe371 and 5 more | 2026-07-23 | N/A | 6.4 MEDIUM |
| A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7. | |||||
| CVE-2026-0414 | 1 Netgear | 2 Rbe970, Rbe970 Firmware | 2026-07-23 | N/A | 4.5 MEDIUM |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |||||
| CVE-2026-0420 | 1 Netgear | 8 Rax120, Rax120 Firmware, Rax35 and 5 more | 2026-07-23 | N/A | 5.9 MEDIUM |
| An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models. | |||||
| CVE-2026-0417 | 1 Netgear | 54 Mr60, Mr60 Firmware, Mr70 and 51 more | 2026-07-23 | N/A | 4.5 MEDIUM |
| Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. | |||||
| CVE-2026-9211 | 1 Netgear | 8 Cax30, Cax30 Firmware, Rax30 and 5 more | 2026-07-23 | N/A | 8.8 HIGH |
| An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. | |||||
| CVE-2026-0416 | 1 Netgear | 4 Raxe450, Raxe450 Firmware, Raxe500 and 1 more | 2026-07-23 | N/A | 4.5 MEDIUM |
| An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality. | |||||
| CVE-2026-0413 | 1 Netgear | 28 Rbe370, Rbe370 Firmware, Rbe770 and 25 more | 2026-07-23 | N/A | 4.5 MEDIUM |
| A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |||||
| CVE-2026-0415 | 1 Netgear | 26 Rbe970, Rbe970 Firmware, Rbr750 and 23 more | 2026-07-23 | N/A | 4.5 MEDIUM |
| Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |||||
| CVE-2023-33532 | 1 Netgear | 2 R6250, R6250 Firmware | 2026-07-09 | N/A | 9.8 CRITICAL |
| There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges. | |||||
| CVE-2022-44194 | 1 Netgear | 2 R7000p, R7000p Firmware | 2026-07-09 | N/A | 9.8 CRITICAL |
| Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec. | |||||
| CVE-2022-30079 | 1 Netgear | 1 R6200 | 2026-07-09 | N/A | 8.8 HIGH |
| Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter. | |||||
| CVE-2022-30078 | 1 Netgear | 4 R6200, R6200 Firmware, R6300 and 1 more | 2026-07-09 | N/A | 8.8 HIGH |
| NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameters. | |||||
| CVE-2021-41449 | 1 Netgear | 6 Rax35, Rax35 Firmware, Rax38 and 3 more | 2026-07-09 | 3.6 LOW | 7.1 HIGH |
| A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet. | |||||
| CVE-2026-0408 | 1 Netgear | 8 Ex2800, Ex2800 Firmware, Ex3110 and 5 more | 2026-06-17 | N/A | 8.0 HIGH |
| A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI. | |||||
| CVE-2026-0407 | 1 Netgear | 8 Ex2800, Ex2800 Firmware, Ex3110 and 5 more | 2026-06-17 | N/A | 8.0 HIGH |
| An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel. | |||||
| CVE-2026-0406 | 1 Netgear | 2 Xr1000v2, Xr1000v2 Firmware | 2026-06-17 | N/A | 8.0 HIGH |
| An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections. | |||||
| CVE-2026-0405 | 1 Netgear | 50 Cbr750, Cbr750 Firmware, Nbr750 and 47 more | 2026-06-17 | N/A | 7.8 HIGH |
| An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin. | |||||
| CVE-2026-0404 | 1 Netgear | 24 Rbr750, Rbr750 Firmware, Rbr840 and 21 more | 2026-06-17 | N/A | 8.0 HIGH |
| An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default. | |||||
| CVE-2026-0403 | 1 Netgear | 20 Rbe970, Rbe970 Firmware, Rbe971 and 17 more | 2026-06-17 | N/A | 8.0 HIGH |
| An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections. | |||||
