Vulnerabilities > Netgear

DATE CVE VULNERABILITY TITLE RISK
2020-06-18 CVE-2020-14427 Unspecified vulnerability in Netgear products
Certain NETGEAR devices are affected by disclosure of administrative credentials.
low complexity
netgear
8.8
2020-06-18 CVE-2020-14426 Unspecified vulnerability in Netgear products
Certain NETGEAR devices are affected by disclosure of administrative credentials.
low complexity
netgear
8.8
2020-06-08 CVE-2020-12695 Incorrect Default Permissions vulnerability in multiple products
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
7.5
2020-05-28 CVE-2020-13245 Improper Certificate Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by Missing SSL Certificate Validation.
network
high complexity
netgear CWE-295
5.9
2020-05-18 CVE-2020-11551 Use of Insufficiently Random Values vulnerability in Netgear Rbs50Y Firmware, Srr60 Firmware and Srs60 Firmware
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106.
low complexity
netgear CWE-330
8.8
2020-05-18 CVE-2020-11550 Unspecified vulnerability in Netgear Rbs50Y Firmware, Srr60 Firmware and Srs60 Firmware
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106.
low complexity
netgear
6.5
2020-05-18 CVE-2020-11549 Use of Hard-coded Credentials vulnerability in Netgear Rbs50Y Firmware, Srr60 Firmware and Srs60 Firmware
An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106.
low complexity
netgear CWE-798
8.8
2020-05-05 CVE-2017-18867 Improper Input Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by incorrect configuration of security settings.
low complexity
netgear CWE-20
6.8
2020-05-05 CVE-2017-18866 Cross-site Scripting vulnerability in Netgear products
Certain NETGEAR devices are affected by stored XSS.
network
low complexity
netgear CWE-79
6.1
2020-05-05 CVE-2017-18865 Out-of-bounds Write vulnerability in Netgear R8300 Firmware and R8500 Firmware
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user.
low complexity
netgear CWE-787
6.8