Vulnerabilidades em Netgear

211 resultados
Análise Vexday

O histórico de vulnerabilidades da Netgear soma 68 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV. Ainda assim, o cenário não é isento de atenção: a CVE-2024-6646, com escore EPSS de 0,46 (o mais alto observado no conjunto), indica probabilidade relevante de exploração e merece acompanhamento prioritário. O tipo de falha mais recorrente é CWE-119 (erros de limitação de operações dentro de um buffer de memória), categoria historicamente associada a impacto elevado em dispositivos de rede e embarcados. Com 3 vulnerabilidades críticas e 2 com PoC pública disponível, o risco de escalada existe, especialmente em ambientes onde patches de firmware são aplicados com menor frequência.

CVE-2018-11106NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following productEPSS 2.6%CVE-2020-27867MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R62EPSS 2.2%CVE-2016-5638Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877 reveals some sensitive information such as 2.4GHz & 5GHz Wireless Network Name (SSID) and Network Key (Password) in clear textEPSS 2.2%CVE-2023-38097HIGHNETGEAR ProSAFE Network Management System BkreProcessThread Exposed Dangerous Function Remote Code Execution VulnerabilityEPSS 2.1%CVE-2023-38101HIGHNETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote Code Execution VulnerabilityEPSS 2.1%CVE-2022-38452HIGHA command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-craftEPSS 2.1%CVE-2024-6814HIGHNETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution VulnerabilityEPSS 2.1%CVE-2020-27861HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. AEPSS 2.0%CVE-2019-5055HIGHAn exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with FirmwareEPSS 2.0%CVE-2022-36429HIGHA command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A speciaEPSS 2.0%CVE-2025-4135MEDIUMNetgear WG302v2 ui_get_input_value command injectionEPSS 1.9%CVE-2020-10929HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 1.9%CVE-2024-6813HIGHNETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2025-4149HIGHNetgear EX6200 sub_54014 buffer overflowEPSS 1.6%CVE-2025-4148HIGHNetgear EX6200 sub_503FC buffer overflowEPSS 1.6%CVE-2025-4150HIGHNetgear EX6200 sub_54340 buffer overflowEPSS 1.5%CVE-2021-34978HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 rouEPSS 1.5%CVE-2022-27647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.9EPSS 1.5%CVE-2022-27646HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.9EPSS 1.4%CVE-2020-10925HIGHThis vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEPSS 1.4%