Vulnerabilities > Netgear > Xr1000 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-11 CVE-2024-35517 Command Injection vulnerability in Netgear Xr1000 Firmware 1.0.0.64
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
network
low complexity
netgear CWE-77
7.2
2021-12-26 CVE-2021-45510 Unspecified vulnerability in Netgear Xr1000 Firmware 1.0.0.44/1.0.0.50/1.0.0.52
NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass.
low complexity
netgear
8.8
2021-12-26 CVE-2021-45514 Command Injection vulnerability in Netgear Xr1000 Firmware 1.0.0.44/1.0.0.50/1.0.0.52
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2021-12-26 CVE-2021-45522 Use of Hard-coded Credentials vulnerability in Netgear Xr1000 Firmware 1.0.0.44/1.0.0.50/1.0.0.52
NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.
low complexity
netgear CWE-798
8.8
2021-12-26 CVE-2021-45654 Information Exposure vulnerability in Netgear Xr1000 Firmware 1.0.0.44/1.0.0.50/1.0.0.52
NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information.
network
low complexity
netgear CWE-200
7.5