Skip to main content

Vendor archive

netgear CVEs

Beta · best-effort

1,334 CVEs tagged to vendor netgear199 Critical, 561 High, 536 Medium, 38 Low, 0 Unrated.

CVE-2024-36788

Published Jun 7, 2024

Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-36787

Published Jun 7, 2024

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-36795

Published Jun 6, 2024

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5505

Published Jun 6, 2024

NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5247

Published May 23, 2024

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5246

Published May 23, 2024

NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5245

Published May 23, 2024

NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affecte…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50231

Published May 3, 2024

NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-44450

Published May 3, 2024

NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44449

Published May 3, 2024

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on af…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41183

Published May 3, 2024

NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR O…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41182

Published May 3, 2024

NETGEAR ProSAFE Network Management System ZipUtils Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-40480

Published May 3, 2024

NETGEAR RAX30 DHCP Server Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected install…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40479

Published May 3, 2024

NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38102

Published May 3, 2024

NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38101

Published May 3, 2024

NETGEAR ProSAFE Network Management System SettingConfigController Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38100

Published May 3, 2024

NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on af…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38099

Published May 3, 2024

NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38098

Published May 3, 2024

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 1,334 CVEsPage 7 of 54