Vulnerabilities > Netgear > R6900 Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-09-21 | CVE-2021-40847 | Cleartext Transmission of Sensitive Information vulnerability in Netgear products The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. | 9.3 |
2021-08-11 | CVE-2021-38539 | Unspecified vulnerability in Netgear products Certain NETGEAR devices are affected by privilege escalation. | 6.5 |
2021-08-11 | CVE-2021-38514 | Unspecified vulnerability in Netgear products Certain NETGEAR devices are affected by authentication bypass. | 4.0 |
2021-08-11 | CVE-2021-38516 | Unspecified vulnerability in Netgear products Certain NETGEAR devices are affected by lack of access control at the function level. | 10.0 |
2021-08-11 | CVE-2021-38520 | Command Injection vulnerability in Netgear products Certain NETGEAR devices are affected by command injection by an authenticated user. | 6.5 |
2021-03-23 | CVE-2021-29068 | Classic Buffer Overflow vulnerability in Netgear products Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. | 6.5 |
2021-02-12 | CVE-2020-27867 | Command Injection vulnerability in Netgear products This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. | 7.7 |
2021-02-12 | CVE-2020-27866 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Netgear products This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. | 8.3 |
2021-02-04 | CVE-2020-27873 | Incorrect Authorization vulnerability in Netgear products This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. | 3.3 |
2021-02-04 | CVE-2020-27872 | Exposure of Resource to Wrong Sphere vulnerability in Netgear products This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. | 5.8 |