Vulnerabilities in NETGEAR

211 results
Vexday analysis

Com 126 CVEs catalogadas, a superfície de ataque dos dispositivos NETGEAR concentra atenção em CWE-121 (Stack-based Buffer Overflow) como tipo de falha mais recorrente, o que é característico de equipamentos embarcados com restrições de desenvolvimento seguro. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com zero entradas confirmadas, mas o escore EPSS de 0,8734 associado a CVE-2020-10924 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção mesmo na ausência de confirmação formal no KEV. Os 17 registros surgidos nos últimos 90 dias sinalizam ritmo contínuo de descobertas, e a presença de 5 CVEs críticas somada a 2 com PoC pública representa risco concreto para ambientes que mantêm firmware desatualizado. Organizações com equipamentos NETGEAR em produção devem priorizar a verificação do status de CVE-2020-10924 e acompanhar de perto o fluxo recente de novas divulgações.

CVE-2023-48725HIGHA stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7EPSS 19.4%CVE-2023-41183HIGHNETGEAR Orbi 760 SOAP API Authentication Bypass VulnerabilityEPSS 13.6%CVE-2023-38098HIGHNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 12.7%CVE-2025-7407MEDIUMNetgear D6400 diag.cgi os command injectionEPSS 10.6%CVE-2016-5649Netgear DGN2200 and DGND3700 disclose the administrator passwordEPSS 9.4%CVE-2020-27866HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R622EPSS 8.7%CVE-2020-15636HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900,EPSS 8.5%CVE-2021-27274CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System EPSS 8.2%CVE-2013-10060CRITICALNetgear Routers pppoe.cgi RCEEPSS 6.5%CVE-2020-15416HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 rEPSS 6.4%CVE-2013-10061HIGHNetgear Routers setup.cgi RCEEPSS 6.3%CVE-2021-34991HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.8EPSS 5.7%CVE-2019-5054HIGHAn exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware VerEPSS 3.1%CVE-2021-34865HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. AuthentEPSS 3.1%CVE-2023-0849MEDIUMNetgear WNDR3700v2 Web Interface command injectionEPSS 2.8%CVE-2022-37337CRITICALA command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTPEPSS 2.8%CVE-2025-4121MEDIUMNetgear JWNR2000v2 cmd_wireless command injectionEPSS 2.8%CVE-2019-17137CRITICALThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware verEPSS 2.7%CVE-2025-4122MEDIUMNetgear JWNR2000v2 sub_435E04 command injectionEPSS 2.7%CVE-2020-15635HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 2.6%