Vulnerabilities > Netgear > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-28 CVE-2023-2385 Cross-site Scripting vulnerability in Netgear Srx5308 Firmware 4.3.53
A vulnerability was found in Netgear SRX5308 up to 4.3.5-3.
network
low complexity
netgear CWE-79
4.8
2023-04-28 CVE-2023-2380 Improper Resource Shutdown or Release vulnerability in Netgear Srx5308 Firmware 4.3.53
A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3.
network
low complexity
netgear CWE-404
6.5
2023-04-28 CVE-2023-2381 Cross-site Scripting vulnerability in Netgear Srx5308 Firmware 4.3.53
A vulnerability has been found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic.
network
low complexity
netgear CWE-79
4.8
2023-04-28 CVE-2023-2382 Cross-site Scripting vulnerability in Netgear Srx5308 Firmware 4.3.53
A vulnerability was found in Netgear SRX5308 up to 4.3.5-3 and classified as problematic.
network
low complexity
netgear CWE-79
4.8
2023-03-21 CVE-2022-38458 Missing Encryption of Sensitive Data vulnerability in Netgear Rbs750 Firmware 4.6.8.5
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5.
network
high complexity
netgear CWE-311
5.9
2023-03-10 CVE-2023-27850 Unspecified vulnerability in Netgear Rax30 Firmware
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.
low complexity
netgear
6.8
2023-01-26 CVE-2022-47052 Injection vulnerability in Netgear Ac1200 R6220 Firmware 1.1.0.1121.0.1/1.1.0.1141.0.1
The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection.
network
low complexity
netgear CWE-74
6.1
2022-12-20 CVE-2022-46422 Unspecified vulnerability in Netgear Wnr2000 Firmware
An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.
network
high complexity
netgear
4.8
2022-09-20 CVE-2022-38956 Improper Validation of Integrity Check Value vulnerability in Netgear Wpn824Ext Firmware 1.1.11.1.9
An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender.
network
high complexity
netgear CWE-354
5.3
2022-06-17 CVE-2022-31876 Unspecified vulnerability in Netgear Wnap320 Firmware 2.0.3
netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.
network
low complexity
netgear
5.3