Vulnerabilities > Netgear
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-14 | CVE-2024-35518 | Command Injection vulnerability in Netgear Ex6120 Firmware Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter. | 6.8 |
2024-10-14 | CVE-2024-35519 | Command Injection vulnerability in Netgear Ex3700 Firmware, Ex6100 Firmware and Ex6120 Firmware Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter. | 6.8 |
2024-10-14 | CVE-2024-35520 | Command Injection vulnerability in Netgear R7000 Firmware 1.0.11.136 Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter. | 6.8 |
2024-10-11 | CVE-2024-35517 | Command Injection vulnerability in Netgear Xr1000 Firmware 1.0.0.64 Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter. | 7.2 |
2024-10-11 | CVE-2024-35522 | Command Injection vulnerability in Netgear Ex3700 Firmware Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone. | 7.2 |
2024-08-21 | CVE-2024-6813 | SQL Injection vulnerability in Netgear Prosafe Network Management System 1.7.0.34 NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. | 8.8 |
2024-08-21 | CVE-2024-6814 | SQL Injection vulnerability in Netgear Prosafe Network Management System 1.7.0.34 NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. | 8.8 |
2024-06-07 | CVE-2024-36788 | Unspecified vulnerability in Netgear Wnr614 Firmware 1.1.0.541.0.1 Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. | 4.8 |
2024-06-06 | CVE-2024-5505 | Path Traversal vulnerability in Netgear Prosafe Network Management System NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. | 8.8 |
2024-02-11 | CVE-2024-1431 | Unspecified vulnerability in Netgear R7000 Firmware 1.0.11.13610.2.120 A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. low complexity netgear | 6.5 |