Vulnerabilities > Netgear

DATE CVE VULNERABILITY TITLE RISK
2017-04-21 CVE-2016-1557 Information Exposure vulnerability in Netgear products
Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.
network
low complexity
netgear CWE-200
critical
9.8
2017-04-21 CVE-2016-1556 Information Exposure vulnerability in Netgear products
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.
network
low complexity
netgear CWE-200
7.5
2017-04-21 CVE-2016-1555 Command Injection vulnerability in Netgear products
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands.
network
low complexity
netgear CWE-77
critical
9.8
2017-03-15 CVE-2017-6366 Cross-Site Request Forgery (CSRF) vulnerability in Netgear Dgn2200 Firmware
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi.
network
low complexity
netgear CWE-352
8.8
2017-03-06 CVE-2017-6334 OS Command Injection vulnerability in Netgear Dgn2200 Series Firmware 10.0.0.50
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.
network
low complexity
netgear CWE-78
8.8
2017-02-22 CVE-2017-6077 OS Command Injection vulnerability in Netgear Dgn2200 Firmware
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
network
low complexity
netgear CWE-78
critical
9.8
2017-01-30 CVE-2016-10176 Improper Input Validation vulnerability in Netgear Wnr2000V5 Firmware 1.0.0.34
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device.
network
low complexity
netgear CWE-20
critical
9.8
2017-01-30 CVE-2016-10175 Information Exposure vulnerability in Netgear Wnr2000V5 Firmware 1.0.0.34
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI.
network
low complexity
netgear CWE-200
critical
9.8
2017-01-30 CVE-2016-10174 Classic Buffer Overflow vulnerability in Netgear products
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html.
network
low complexity
netgear CWE-120
critical
9.8
2017-01-17 CVE-2017-5521 Unspecified vulnerability in Netgear products
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices.
network
high complexity
netgear
8.1