Vulnerabilities in NETGEAR

211 results
Vexday analysis

Com 126 CVEs catalogadas, a superfície de ataque dos dispositivos NETGEAR concentra atenção em CWE-121 (Stack-based Buffer Overflow) como tipo de falha mais recorrente, o que é característico de equipamentos embarcados com restrições de desenvolvimento seguro. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com zero entradas confirmadas, mas o escore EPSS de 0,8734 associado a CVE-2020-10924 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção mesmo na ausência de confirmação formal no KEV. Os 17 registros surgidos nos últimos 90 dias sinalizam ritmo contínuo de descobertas, e a presença de 5 CVEs críticas somada a 2 com PoC pública representa risco concreto para ambientes que mantêm firmware desatualizado. Organizações com equipamentos NETGEAR em produção devem priorizar a verificação do status de CVE-2020-10924 e acompanhar de perto o fluxo recente de novas divulgações.

CVE-2023-38100HIGHNETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation VulnerabilityEPSS 1.4%CVE-2025-4146HIGHNetgear EX6200 sub_41940 buffer overflowEPSS 1.4%CVE-2023-38102HIGHNETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation VulnerabilityEPSS 1.4%CVE-2020-15634MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 routers with firmwEPSS 1.4%CVE-2021-34979HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 rouEPSS 1.4%CVE-2021-34980HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 rouEPSS 1.4%CVE-2023-27367HIGHNETGEAR RAX30 libcms_cli Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2023-51635HIGHNETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-2380MEDIUMNetgear SRX5308 denial of serviceEPSS 1.3%CVE-2022-27645HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. AuthentiEPSS 1.3%CVE-2020-15417MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 1.3%CVE-2013-10063MEDIUMNetgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GETEPSS 1.3%CVE-2023-40479HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-40480HIGHNETGEAR RAX30 DHCP Server Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2021-27255MEDIUMThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. AEPSS 1.3%CVE-2023-35722HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2022-27641HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.9EPSS 1.2%CVE-2023-27356MEDIUMNETGEAR RAX30 logCtrl Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2020-10926HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 1.2%CVE-2026-0404MEDIUMInsufficient input validation in NETGEAR Orbi routersEPSS 1.2%