netgear

1,325 tracked vulnerabilities.

CVE-2024-51012 MEDIUM
Netgear R8500 v1.0.2.160 - Denial of Service via ipv6_pri_dns Parameter Overflow
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51011 MEDIUM
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400v2 1.0.4.128 - Stack Overflow via pppoe_localip Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51010 HIGH
Netgear R8500/R7000P/R6400v2/XR300 OS Command Injection via apmode_gateway
Nov 05, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-51009 HIGH
Netgear R8500 v1.0.2.160 - OS Command Injection via wan_gateway Parameter
Nov 05, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-51008 HIGH
Netgear XR300 v1.0.3.78 - OS Command Injection via system_name Parameter
Nov 05, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-51007 MEDIUM
Netgear XR300 Firmware v1.0.3.78 - Stack Overflow via wireless.cgi Passphrase Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51006 MEDIUM
Netgear R8500 v1.0.2.160 - Stack Overflow via ipv6_static_ip Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51005 HIGH
Netgear R8500 Firmware 1.0.2.160 - OS Command Injection via share_name Parameter
Nov 05, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-51004 MEDIUM
Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 - Denial of Service via Stack Overflow in usb_device.cgi
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51003 MEDIUM
Netgear R8500/R7000P/R6400v2/XR300 Stack Overflow via apmode_dns1_pri/apmode_dns1_sec
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51002 MEDIUM
Netgear R8500/R7000P/XR300/R6400v2 Firmware - Stack Overflow via l2tp_user_ip Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51001 MEDIUM
Netgear R8500 Firmware 1.0.2.160 - Stack Overflow via sysDNSHost Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-51000 MEDIUM
Netgear R8500 Firmware 1.0.2.160 - Denial of Service via wireless.cgi Parameter Overflow
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50999 MEDIUM
Netgear R8500 v1.0.2.160 - OS Command Injection via sysNewPasswd Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50998 MEDIUM
Netgear R8500 Firmware 1.0.2.160 - Stack Overflow via openvpn.cgi Parameters
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50997 MEDIUM
Netgear R8500/R7000P/R6400v2/XR300 DoS via pptp_user_ip Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50996 MEDIUM
Netgear R8500 R7000P R6400v2 XR300 - Denial of Service via bpa_server Parameter Overflow
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50995 MEDIUM
Netgear R8500 v1.0.2.160 - Stack Overflow via share_name Parameter
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50994 MEDIUM
Netgear R8500 v1.0.2.160 - Denial of Service via ipv6_fix.cgi Parameter Overflow
Nov 05, 2024
CVSS 5.7
EPSS 0.00
CVE-2024-50993 HIGH
Netgear R8500 v1.0.2.160 - OS Command Injection via sysNewPasswd Parameter
Nov 05, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-35520 HIGH
Netgear R7000 1.0.11.136 - Command Injection via RMT_invite.cgi device_name2 Parameter
Oct 14, 2024
CVSS 8.4
EPSS 0.05
CVE-2024-35519 HIGH
Netgear EX3700 < 1.0.0.96, EX6100 < 1.0.2.28, EX6120 < 1.0.0.68 - OS Command Injection via ap_mode Parameter
Oct 14, 2024
CVSS 8.4
EPSS 0.00
CVE-2024-35518 HIGH
Netgear EX6120 < 1.0.0.68 - OS Command Injection via wan_dns1_pri Parameter
Oct 14, 2024
CVSS 8.4
EPSS 0.00
CVE-2024-35522 HIGH
Netgear EX3700 Firmware < 1.0.0.98 - Authenticated Command Injection via ap_mode Parameter
Oct 11, 2024
CVSS 8.4
EPSS 0.01
CVE-2024-35517 HIGH
Netgear XR1000 v1.0.0.64 - OS Command Injection via usb_remote_smb_conf.cgi share_name Parameter
Oct 11, 2024
CVSS 8.4
EPSS 0.11