Vulnerabilities > Netgear > R6200 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2022-09-07 CVE-2022-30078 OS Command Injection vulnerability in Netgear R6200 Firmware and R6300 Firmware
NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameters.
network
low complexity
netgear CWE-78
8.8
2020-04-28 CVE-2016-11059 Information Exposure vulnerability in Netgear products
Certain NETGEAR devices are affected by password exposure.
network
low complexity
netgear CWE-200
7.5
2020-04-21 CVE-2017-18799 Improper Input Validation vulnerability in Netgear products
Certain NETGEAR devices are affected by incorrect configuration of security settings.
network
low complexity
netgear CWE-20
7.5
2019-10-09 CVE-2019-17372 Improper Authentication vulnerability in Netgear products
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi.
network
high complexity
netgear CWE-287
8.1
2017-01-17 CVE-2017-5521 Unspecified vulnerability in Netgear products
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices.
network
high complexity
netgear
8.1