Vulnerabilidades em Netgear

200 resultados
Análise Vexday

O histórico de vulnerabilidades da Netgear soma 68 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV. Ainda assim, o cenário não é isento de atenção: a CVE-2024-6646, com escore EPSS de 0,46 (o mais alto observado no conjunto), indica probabilidade relevante de exploração e merece acompanhamento prioritário. O tipo de falha mais recorrente é CWE-119 (erros de limitação de operações dentro de um buffer de memória), categoria historicamente associada a impacto elevado em dispositivos de rede e embarcados. Com 3 vulnerabilidades críticas e 2 com PoC pública disponível, o risco de escalada existe, especialmente em ambientes onde patches de firmware são aplicados com menor frequência.

CVE-2023-48725HIGHA stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7EPSS 19.4%CVE-2025-4978CRITICALNetgear DGND3700 Basic Authentication BRS_top.html improper authenticationEPSS 17.8%CVE-2023-41183HIGHNETGEAR Orbi 760 SOAP API Authentication Bypass VulnerabilityEPSS 15.3%CVE-2023-38098HIGHNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 12.7%CVE-2025-7407MEDIUMNetgear D6400 diag.cgi os command injectionEPSS 8.7%CVE-2020-27866HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R622EPSS 8.7%CVE-2020-15636HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900,EPSS 8.5%CVE-2021-27274CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System EPSS 8.2%CVE-2020-15416HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 rEPSS 6.4%CVE-2021-34991HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.8EPSS 5.7%CVE-2013-10060CRITICALNetgear Routers pppoe.cgi RCEEPSS 4.5%CVE-2013-10061HIGHNetgear Routers setup.cgi RCEEPSS 4.4%CVE-2019-5054HIGHAn exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware VerEPSS 3.1%CVE-2021-34865HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. AuthentEPSS 3.1%CVE-2023-0849MEDIUMNetgear WNDR3700v2 Web Interface command injectionEPSS 2.8%CVE-2022-37337CRITICALA command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTPEPSS 2.8%CVE-2016-5638Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877 reveals some sensitive information such as 2.4GHz & 5GHz Wireless Network Name (SSID) and Network Key (Password) in clear textEPSS 2.8%CVE-2025-4121MEDIUMNetgear JWNR2000v2 cmd_wireless command injectionEPSS 2.7%CVE-2019-17137CRITICALThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware verEPSS 2.7%CVE-2020-15635HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 EPSS 2.6%