Vulnerabilities > Netgear

DATE CVE VULNERABILITY TITLE RISK
2018-07-24 CVE-2016-5649 Information Exposure vulnerability in Netgear Dgn2200 Firmware and Dgnd3700 Firmware
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication.
network
low complexity
netgear CWE-200
5.0
2018-07-24 CVE-2016-5638 Information Exposure vulnerability in Netgear Wndr4500 Firmware 1.0.1.401.0.6877
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877.
network
low complexity
netgear CWE-200
5.0
2017-05-26 CVE-2017-6862 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Netgear products
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp.
network
low complexity
netgear CWE-119
critical
9.8
2017-04-28 CVE-2017-2137 Unspecified vulnerability in Netgear Prosafe Plus Configuration Utility
ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.
network
netgear
4.3
2017-04-21 CVE-2016-1557 Information Exposure vulnerability in Netgear products
Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.
network
low complexity
netgear CWE-200
5.0
2017-04-21 CVE-2016-1556 Information Exposure vulnerability in Netgear products
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.
network
low complexity
netgear CWE-200
5.0
2017-04-21 CVE-2016-1555 Command Injection vulnerability in Netgear products
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
network
low complexity
netgear CWE-77
critical
10.0
2017-03-15 CVE-2017-6366 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Dgn2200 Firmware
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi.
network
netgear CWE-352
6.8
2017-03-06 CVE-2017-6334 OS Command Injection vulnerability in Netgear Dgn2200 Series Firmware
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
network
low complexity
netgear CWE-78
critical
9.0
2017-02-22 CVE-2017-6077 OS Command Injection vulnerability in Netgear Dgn2200 Firmware
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
network
low complexity
netgear CWE-78
critical
10.0