Vulnerabilities > Netgear > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-15 CVE-2023-50089 Command Injection vulnerability in Netgear Wnr2000 Firmware 1.0.0.70
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70.
network
low complexity
netgear CWE-77
critical
9.8
2023-12-08 CVE-2023-49007 Out-of-bounds Write vulnerability in Netgear Rbr750 Firmware
In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.
network
low complexity
netgear CWE-787
critical
9.8
2023-11-29 CVE-2023-49693 Missing Authentication for Critical Function vulnerability in Netgear Prosafe Network Management System
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.
network
low complexity
netgear CWE-306
critical
9.8
2023-09-01 CVE-2023-36187 Classic Buffer Overflow vulnerability in Netgear products
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
network
low complexity
netgear CWE-120
critical
9.8
2023-08-07 CVE-2023-38928 Command Injection vulnerability in Netgear R7100Lg Firmware 1.0.0.78
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.
network
low complexity
netgear CWE-77
critical
9.8
2023-06-20 CVE-2023-34563 Classic Buffer Overflow vulnerability in Netgear R6250 Firmware 1.0.4.48
netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
network
low complexity
netgear CWE-120
critical
9.8
2023-06-06 CVE-2023-33532 Command Injection vulnerability in Netgear R6250 Firmware 1.0.4.48
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48.
network
low complexity
netgear CWE-77
critical
9.8
2023-04-26 CVE-2023-30280 Classic Buffer Overflow vulnerability in Netgear R6700 Firmware and R6900 Firmware
Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.
network
low complexity
netgear CWE-120
critical
9.8
2023-03-14 CVE-2023-1327 Improper Authentication vulnerability in Netgear Rax30 Firmware 1.0.3.64/1.0.4.66/1.0.5.70
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.
network
low complexity
netgear CWE-287
critical
9.8
2023-03-10 CVE-2023-27853 Classic Buffer Overflow vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.
network
low complexity
netgear CWE-120
critical
9.8