Vulnerabilidades em NETGEAR

211 resultados
Análise Vexday

Com 126 CVEs catalogadas, a superfície de ataque dos dispositivos NETGEAR concentra atenção em CWE-121 (Stack-based Buffer Overflow) como tipo de falha mais recorrente, o que é característico de equipamentos embarcados com restrições de desenvolvimento seguro. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com zero entradas confirmadas, mas o escore EPSS de 0,8734 associado a CVE-2020-10924 indica alta probabilidade estimada de exploração para essa vulnerabilidade específica, exigindo atenção mesmo na ausência de confirmação formal no KEV. Os 17 registros surgidos nos últimos 90 dias sinalizam ritmo contínuo de descobertas, e a presença de 5 CVEs críticas somada a 2 com PoC pública representa risco concreto para ambientes que mantêm firmware desatualizado. Organizações com equipamentos NETGEAR em produção devem priorizar a verificação do status de CVE-2020-10924 e acompanhar de perto o fluxo recente de novas divulgações.

CVE-2025-5495MEDIUMNetgear WNR614 URL improper authenticationEPSS 0.9%CVE-2025-4115HIGHNetgear JWNR2000v2 default_version_is_new buffer overflowEPSS 0.9%CVE-2025-4116HIGHNetgear JWNR2000v2 get_cur_lang_ver buffer overflowEPSS 0.9%CVE-2020-10930MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_EPSS 0.9%CVE-2020-10927HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 0.9%CVE-2026-11814MEDIUMCommand injection vulnerability in certain NETGEAR Nighthawk and Orbi routersEPSS 0.9%CVE-2020-27872HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routEPSS 0.9%CVE-2023-34285HIGHNETGEAR RAX30 cmsCli_authenticate Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.9%CVE-2021-34870MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_EPSS 0.9%CVE-2025-6510HIGHNetgear EX6100 sub_415EF8 stack-based overflowEPSS 0.9%CVE-2023-0848MEDIUMNetgear WNDR3700v2 Web Management Interface denial of serviceEPSS 0.9%CVE-2022-27642MEDIUMThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91EPSS 0.9%CVE-2023-27358HIGHNETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2021-27256HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1EPSS 0.9%CVE-2023-27361MEDIUMNETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-12988MEDIUMNetgear R6900P/R7000P HTTP Header sub_16C4C buffer overflowEPSS 0.8%CVE-2023-40478HIGHNETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.8%CVE-2025-6565HIGHNetgear WNCE3001 HTTP POST Request http_d stack-based overflowEPSS 0.8%CVE-2024-12147HIGHNetgear R6900 HTTP Header upgrade_check.cgi buffer overflowEPSS 0.8%CVE-2023-2395MEDIUMNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.8%