Vulnerabilities > Netgear > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-03-14 CVE-2023-1327 Improper Authentication vulnerability in Netgear Rax30 Firmware 1.0.3.64/1.0.4.66/1.0.5.70
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.
network
low complexity
netgear CWE-287
critical
9.8
2023-03-10 CVE-2023-27852 Classic Buffer Overflow vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.
network
low complexity
netgear CWE-120
critical
9.8
2023-03-10 CVE-2023-27853 Classic Buffer Overflow vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.
network
low complexity
netgear CWE-120
critical
9.8
2023-02-15 CVE-2023-0849 Unspecified vulnerability in Netgear Wndr3700 Firmware 1.0.1.14
A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical.
network
low complexity
netgear
critical
9.8
2023-02-13 CVE-2022-48322 Out-of-bounds Write vulnerability in Netgear products
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability.
network
low complexity
netgear CWE-787
critical
9.8
2022-12-30 CVE-2022-48196 Classic Buffer Overflow vulnerability in Netgear products
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker.
network
low complexity
netgear CWE-120
critical
9.8
2022-12-09 CVE-2022-4390 Unspecified vulnerability in Netgear Ax2400 Firmware
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers.
network
low complexity
netgear
critical
10.0
2022-11-22 CVE-2022-44184 Out-of-bounds Write vulnerability in Netgear R7000P Firmware 1.3.0.8
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.
network
low complexity
netgear CWE-787
critical
9.8
2022-11-22 CVE-2022-44186 Out-of-bounds Write vulnerability in Netgear R7000P Firmware 1.3.1.64
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.
network
low complexity
netgear CWE-787
critical
9.8
2022-11-22 CVE-2022-44187 Out-of-bounds Write vulnerability in Netgear R7000P Firmware 1.3.0.8
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.
network
low complexity
netgear CWE-787
critical
9.8