Skip to main content

Vendor archive

netgear CVEs

Beta · best-effort

1,334 CVEs tagged to vendor netgear199 Critical, 561 High, 536 Medium, 38 Low, 0 Unrated.

CVE-2015-6312

Published Apr 6, 2016

Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denia…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1525

Published Feb 13, 2016

Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-1524

Published Feb 13, 2016

Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileU…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-8263

Published Dec 27, 2015

NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting th…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4864

Published Sep 10, 2014

The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive informatio…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2969

Published Jul 7, 2014

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote attackers to upload firmware o…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-3069

Published Apr 25, 2014

Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1)…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4775

Published Dec 19, 2013

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS…

CVSS 7.8 · High

CVE-2013-2752

Published Dec 12, 2013

Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2751

Published Dec 12, 2013

Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attack…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-2439

Published Apr 28, 2012

The default configuration of the NETGEAR ProSafe FVS318N firewall enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2258

Published Jun 30, 2009

Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary direct…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2257

Published Jun 30, 2009

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,276-1,300 of 1,334 CVEsPage 52 of 54