Vulnerabilidades en NETGEAR

211 resultados
Análisis Vexday

Com 126 CVEs catalogadas, a superfície de ataque dos dispositivos NETGEAR concentra atenção em CWE-121 (Stack-based Buffer Overflow) como tipo de falha mais recorrente, o que é característico de equipamentos embarcados com restrições de desenvolvimento seguro. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com zero entradas confirmadas, mas o escore EPSS de 0,8734 associado a CVE-2020-10924 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção mesmo na ausência de confirmação formal no KEV. Os 17 registros surgidos nos últimos 90 dias sinalizam ritmo contínuo de descobertas, e a presença de 5 CVEs críticas somada a 2 com PoC pública representa risco concreto para ambientes que mantêm firmware desatualizado. Organizações com equipamentos NETGEAR em produção devem priorizar a verificação do status de CVE-2020-10924 e acompanhar de perto o fluxo recente de novas divulgações.

CVE-2026-11733LOWBuffer overflow vulnerability in some NETGEAR Nighthawk routersEPSS 0.5%CVE-2026-11735LOWStack-based buffer overflow vulnerability in some NETGEAR Nighthawk modelsEPSS 0.5%CVE-2026-11736LOWStack-based buffer overflow vulnerability in some NETGEAR Nighthawk routersEPSS 0.5%CVE-2024-7153MEDIUMNetgear WN604 siteSurvey.php direct requestEPSS 0.5%CVE-2021-27254MEDIUMThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is EPSS 0.5%CVE-2023-27360HIGHNETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-34284MEDIUMNETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-9213MEDIUMInsufficient input validation in certain NETGEAR routersEPSS 0.4%CVE-2026-0405MEDIUMAuthentication Bypass in NETGEAR Orbi DevicesEPSS 0.4%CVE-2026-3088MEDIUMUnauthenticated users can disrupt router operationEPSS 0.4%CVE-2022-27644MEDIUMThis vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEPSS 0.3%CVE-2023-27370MEDIUMNETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure VulnerabilityEPSS 0.3%CVE-2021-34983MEDIUMNETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure VulnerabilityEPSS 0.3%CVE-2026-62655MEDIUMA DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi modelsEPSS 0.3%CVE-2026-0403LOWInsufficient input validation in NETGEAR Orbi routersEPSS 0.3%CVE-2026-0413MEDIUMBuffer overflow vulnerability in certain NETGEAR Nighthawk routersEPSS 0.3%CVE-2021-27257MEDIUMThis vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEPSS 0.3%CVE-2026-62658MEDIUMPost-authentication Command Injection Vulnerability in certain Nighthawk RAX series modelsEPSS 0.3%CVE-2025-12942MEDIUMImproper input validation in NETGEAR R6260 and R6850EPSS 0.3%CVE-2025-12946MEDIUMImproper input validation in NETGEAR Nighthawk routersEPSS 0.3%