Vulnerabilities > Netgear > Dgn2200 Firmware > 1.0.0.110

DATE CVE VULNERABILITY TITLE RISK
2020-04-28 CVE-2016-11059 Information Exposure vulnerability in Netgear products
Certain NETGEAR devices are affected by password exposure.
network
low complexity
netgear CWE-200
7.5
2020-04-28 CVE-2016-11054 OS Command Injection vulnerability in Netgear Dgn2200 Firmware
NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.
network
low complexity
netgear CWE-78
7.2
2017-03-15 CVE-2017-6366 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Dgn2200 Firmware
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi.
network
low complexity
netgear CWE-352
8.8
2017-02-22 CVE-2017-6077 OS Command Injection vulnerability in Netgear Dgn2200 Firmware
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
network
low complexity
netgear CWE-78
critical
9.8