Vulnerabilities > Netgear > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2013-4657 Path Traversal vulnerability in Netgear Wnr3500L Firmware and Wnr3500U Firmware
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
network
low complexity
netgear CWE-22
critical
9.8
2019-10-16 CVE-2016-11014 Insufficient Session Expiration vulnerability in Netgear Jnr1010 Firmware
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
network
low complexity
netgear CWE-613
critical
9.8
2019-10-09 CVE-2019-17373 Unspecified vulnerability in Netgear products
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL.
network
low complexity
netgear
critical
9.8
2019-08-14 CVE-2019-14527 OS Command Injection vulnerability in Netgear Mr1100 Firmware 12.05.05.00
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03.
network
low complexity
netgear CWE-78
critical
9.8
2019-07-28 CVE-2019-14363 Out-of-bounds Write vulnerability in Netgear Wndr3400V3 Firmware 1.0.1.18/1.0.1.22/1.0.1.24
A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to remotely execute arbitrary code via a crafted UPnP SSDP packet.
network
low complexity
netgear CWE-787
critical
9.8
2019-06-17 CVE-2019-5016 Information Exposure vulnerability in multiple products
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potentially several other vendors/products.
network
low complexity
netgear kcodes CWE-200
critical
9.1
2019-06-11 CVE-2017-18378 Command Injection vulnerability in Netgear Readynas Surveillance Firmware
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
network
low complexity
netgear CWE-77
critical
9.8
2018-07-24 CVE-2016-5649 Information Exposure vulnerability in Netgear Dgn2200 Firmware and Dgnd3700 Firmware
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication.
network
low complexity
netgear CWE-200
critical
9.8
2017-05-26 CVE-2017-6862 Classic Buffer Overflow vulnerability in Netgear products
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp.
network
low complexity
netgear CWE-120
critical
9.8
2017-04-21 CVE-2016-1557 Information Exposure vulnerability in Netgear products
Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.
network
low complexity
netgear CWE-200
critical
9.8