Vulnerabilities (CVE)

Filtered by vendor Netgear Subscribe
Total 1335 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-50993 1 Netgear 2 R8500, R8500 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2024-4235 1 Netgear 2 Dg834gv5, Dg834gv5 Firmware 2026-06-17 3.3 LOW 2.7 LOW
A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads to cleartext storage of sensitive information. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-262126 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-42756 1 Netgear 2 Dgn1000ww, Dgn1000ww Firmware 2026-06-17 N/A 8.8 HIGH
An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page
CVE-2024-36795 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 4.0 MEDIUM
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.
CVE-2024-36792 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.2 HIGH
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
CVE-2024-36790 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
CVE-2024-36789 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.1 HIGH
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
CVE-2024-36788 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 4.8 MEDIUM
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.
CVE-2024-36787 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
CVE-2024-35522 1 Netgear 2 Ex3700, Ex3700 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone.
CVE-2024-35520 1 Netgear 2 R7000, R7000 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2024-35519 1 Netgear 6 Ex3700, Ex3700 Firmware, Ex6100 and 3 more 2026-06-17 N/A 8.4 HIGH
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
CVE-2024-35518 1 Netgear 2 Ex6120, Ex6120 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
CVE-2024-35517 1 Netgear 2 Xr1000, Xr1000 Firmware 2026-06-17 N/A 8.4 HIGH
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
CVE-2024-30572 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 8.0 HIGH
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
CVE-2024-30571 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 7.5 HIGH
An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30570 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 5.3 MEDIUM
An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30569 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 7.5 HIGH
An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.
CVE-2024-30568 1 Netgear 2 R6850, R6850 Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVE-2024-28340 1 Netgear 6 Cbk40, Cbk40 Firmware, Cbk43 and 3 more 2026-06-17 N/A 7.5 HIGH
An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.