Vulnerabilidades em Netgear

211 resultados
Análise Vexday

O histórico de vulnerabilidades da Netgear soma 68 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV. Ainda assim, o cenário não é isento de atenção: a CVE-2024-6646, com escore EPSS de 0,46 (o mais alto observado no conjunto), indica probabilidade relevante de exploração e merece acompanhamento prioritário. O tipo de falha mais recorrente é CWE-119 (erros de limitação de operações dentro de um buffer de memória), categoria historicamente associada a impacto elevado em dispositivos de rede e embarcados. Com 3 vulnerabilidades críticas e 2 com PoC pública disponível, o risco de escalada existe, especialmente em ambientes onde patches de firmware são aplicados com menor frequência.

CVE-2026-0419MEDIUMInsufficient input validation vulnerability in NETGEAR JR6150EPSS 0.3%CVE-2026-0411MEDIUMA Sensitive Information Disclosure Vulnerability in NETGEAR Orbi SatellitesEPSS 0.3%CVE-2025-12940LOWCredentials recorded in logs in NETGEAR WAX610 and WAX610YEPSS 0.3%CVE-2026-9212MEDIUMInsufficient authentication and input validation in certain NETGEAR productsEPSS 0.3%CVE-2026-11738MEDIUMInsufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.EPSS 0.3%CVE-2026-0409MEDIUMNetgear Orbi 370 Series Remote Code Execution vulnerabilityEPSS 0.3%CVE-2026-62656MEDIUMPost-authenticated command injection vulnerability found in certain NETGEAR RAX modelsEPSS 0.3%CVE-2026-0408MEDIUMPath traversal vulnerability in Netgear WiFi Range ExtendersEPSS 0.3%CVE-2026-15757MEDIUMInsufficient input validation vulnerability in NETGEAR DGND3700v1 modem routerEPSS 0.3%CVE-2026-0407MEDIUMAuthentication bypass in NETGEAR WiFi Range Extenders via network adjacent attacksEPSS 0.3%CVE-2025-12944MEDIUMImproper input validation in NETGEAR DGN2200v4EPSS 0.3%CVE-2026-0406MEDIUMInsufficient input validation in NETGEAR Nighthawk router XR1000v2EPSS 0.2%CVE-2026-0418MEDIUMCertain NETGEAR devices allow administrators to tamper with systemEPSS 0.2%CVE-2026-62659MEDIUMAuthenticated users can make unauthorized changes on NETGEAR WAX333 Access PointsEPSS 0.2%CVE-2026-9211MEDIUMCertain NETGEAR routers allow unauthenticated users to gain control of the routerEPSS 0.2%CVE-2026-9216LOWInsufficient input validation vulnerability exists in certain NETGEAR RAX ModelsEPSS 0.2%CVE-2026-0417MEDIUMInsufficient input validation in certain NETGEAR routersEPSS 0.2%CVE-2026-0415MEDIUMInsufficient input validation vulnerability in certain Orbi routersEPSS 0.2%CVE-2026-24714HIGHSome end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the boxEPSS 0.2%CVE-2026-11737MEDIUMSome NETGEAR Nighthawk devices allow administrators to tamper with the deviceEPSS 0.2%