Vulnerabilidades em Netgear

211 resultados
Análise Vexday

O histórico de vulnerabilidades da Netgear soma 68 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV. Ainda assim, o cenário não é isento de atenção: a CVE-2024-6646, com escore EPSS de 0,46 (o mais alto observado no conjunto), indica probabilidade relevante de exploração e merece acompanhamento prioritário. O tipo de falha mais recorrente é CWE-119 (erros de limitação de operações dentro de um buffer de memória), categoria historicamente associada a impacto elevado em dispositivos de rede e embarcados. Com 3 vulnerabilidades críticas e 2 com PoC pública disponível, o risco de escalada existe, especialmente em ambientes onde patches de firmware são aplicados com menor frequência.

CVE-2023-2396MEDIUMNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.8%CVE-2023-27369HIGHNETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass VulnerabilityEPSS 0.8%CVE-2023-27368HIGHNETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass VulnerabilityEPSS 0.8%CVE-2023-44445HIGHNETGEAR CAX30 SSO Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.8%CVE-2021-27239HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmwareEPSS 0.7%CVE-2021-27251HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. AuthentEPSS 0.7%CVE-2020-17409MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6EPSS 0.7%CVE-2025-25246HIGHNETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.EPSS 0.7%CVE-2023-2383LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.7%CVE-2023-2390LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.7%CVE-2023-2389LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.7%CVE-2023-2393LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-2391LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-2394LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-2385LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-2384LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-2392LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-2382LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-34283MEDIUMNETGEAR RAX30 USB Share Link Following Information Disclosure VulnerabilityEPSS 0.6%CVE-2020-10928HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 0.6%