Vulnerabilities (CVE)

Filtered by vendor Netgear Subscribe
Total 1318 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42756 1 Netgear 2 Dgn1000ww, Dgn1000ww Firmware 2026-06-17 N/A 8.8 HIGH
An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page
CVE-2024-36795 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 4.0 MEDIUM
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.
CVE-2024-36792 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.2 HIGH
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
CVE-2024-36790 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
CVE-2024-36789 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.1 HIGH
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
CVE-2024-36788 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 4.8 MEDIUM
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.
CVE-2024-36787 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
CVE-2024-35522 1 Netgear 2 Ex3700, Ex3700 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone.
CVE-2024-35520 1 Netgear 2 R7000, R7000 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2024-35519 1 Netgear 6 Ex3700, Ex3700 Firmware, Ex6100 and 3 more 2026-06-17 N/A 8.4 HIGH
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
CVE-2024-35518 1 Netgear 2 Ex6120, Ex6120 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
CVE-2024-35517 1 Netgear 2 Xr1000, Xr1000 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
CVE-2024-30572 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
CVE-2024-30571 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 7.5 HIGH
An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30570 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 5.3 MEDIUM
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30569 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 7.5 HIGH
An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30568 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVE-2024-28340 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 7.5 HIGH
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-28339 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 5.4 MEDIUM
An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-1431 1 Netgear 2 R7000, R7000 Firmware 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253382 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.