Vulnerabilities > Netgear > Prosafe Network Management System > 1.6.0.26

DATE CVE VULNERABILITY TITLE RISK
2023-11-29 CVE-2023-49693 Missing Authentication for Critical Function vulnerability in Netgear Prosafe Network Management System
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
network
low complexity
netgear CWE-306
critical
9.8
2023-11-29 CVE-2023-49694 Unspecified vulnerability in Netgear Prosafe Network Management System
A low-privileged OS user with access to a Windows host where NETGEAR ProSAFE Network Management System is installed can create arbitrary JSP files in a Tomcat web application directory.
local
low complexity
netgear
7.8
2021-03-29 CVE-2021-27276 Path Traversal vulnerability in Netgear Prosafe Network Management System 1.6.0.26
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.
network
low complexity
netgear CWE-22
5.5
2021-03-29 CVE-2021-27275 Path Traversal vulnerability in Netgear Prosafe Network Management System 1.6.0.26
This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.
network
low complexity
netgear CWE-22
6.5
2021-03-29 CVE-2021-27274 Unrestricted Upload of File with Dangerous Type vulnerability in Netgear Prosafe Network Management System 1.6.0.26
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.
network
low complexity
netgear CWE-434
critical
10.0
2021-03-29 CVE-2021-27273 OS Command Injection vulnerability in Netgear Prosafe Network Management System 1.6.0.26
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.
network
low complexity
netgear CWE-78
critical
9.0
2021-03-29 CVE-2021-27272 Path Traversal vulnerability in Netgear Prosafe Network Management System 1.6.0.26
This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.
network
low complexity
netgear CWE-22
7.5