Vulnerabilities > Netgear > R8500 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-03-29 CVE-2022-27642 Incorrect Authorization vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.
low complexity
netgear CWE-863
8.8
2023-03-29 CVE-2022-27643 Classic Buffer Overflow vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.
low complexity
netgear CWE-120
8.8
2023-03-29 CVE-2022-27647 OS Command Injection vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.
low complexity
netgear CWE-78
8.0
2023-03-29 CVE-2022-27645 Missing Authentication for Critical Function vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers.
low complexity
netgear CWE-306
8.8
2022-03-26 CVE-2022-27945 OS Command Injection vulnerability in Netgear R8500 Firmware 1.0.2.158
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.
network
low complexity
netgear CWE-78
8.8
2022-03-26 CVE-2022-27946 OS Command Injection vulnerability in Netgear R8500 Firmware 1.0.2.158
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi.
network
low complexity
netgear CWE-78
8.8
2022-03-26 CVE-2022-27947 OS Command Injection vulnerability in Netgear R8500 Firmware 1.0.2.158
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter.
network
low complexity
netgear CWE-78
8.8
2021-12-26 CVE-2021-45615 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2021-11-15 CVE-2021-34991 Out-of-bounds Write vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers.
low complexity
netgear CWE-787
8.8
2021-08-11 CVE-2021-38539 Unspecified vulnerability in Netgear products
Certain NETGEAR devices are affected by privilege escalation.
network
low complexity
netgear
8.8