Vulnerabilities (CVE)

Filtered by vendor Netgear Subscribe
Total 1346 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35522 1 Netgear 2 Ex3700, Ex3700 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone.
CVE-2024-35520 1 Netgear 2 R7000, R7000 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2024-35519 1 Netgear 6 Ex3700, Ex3700 Firmware, Ex6100 and 3 more 2026-06-17 N/A 8.4 HIGH
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
CVE-2024-35518 1 Netgear 2 Ex6120, Ex6120 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
CVE-2024-35517 1 Netgear 2 Xr1000, Xr1000 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
CVE-2024-30572 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
CVE-2024-30571 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 7.5 HIGH
An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30570 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 5.3 MEDIUM
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30569 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 7.5 HIGH
An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30568 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVE-2024-28340 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 7.5 HIGH
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-28339 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 5.4 MEDIUM
An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-1431 1 Netgear 2 R7000, R7000 Firmware 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253382 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-1430 1 Netgear 2 R7000, R7000 Firmware 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-12988 1 Netgear 4 R6900p, R6900p Firmware, R7000p and 1 more 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the argument Host leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-12847 1 Netgear 2 Dgn1000, Dgn1000 Firmware 2026-06-17 N/A 9.8 CRITICAL
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at least 2017 and specifically by the Shadowserver Foundation on 2025-02-06 UTC.
CVE-2023-51635 1 Netgear 2 Rax30, Rax30 Firmware 2026-06-17 N/A 8.8 HIGH
NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within fing_dil service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19843.
CVE-2023-51634 1 Netgear 2 Rax30, Rax30 Firmware 2026-06-17 N/A 7.5 HIGH
NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-19589.
CVE-2023-50677 1 Netgear 2 Dgnd4000, Dgnd4000 Firmware 2026-06-17 N/A 8.8 HIGH
An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.
CVE-2023-50231 1 Netgear 1 Prosafe Network Management System 2026-06-17 N/A 9.6 CRITICAL
NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the saveNodeLabel method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-21838.