« Volver al listado

Netgear

Netgear Xr1000 Firmware: vulnerabilidades y CVE

Netgear Xr1000 Firmware tiene 30 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE30
Últimos 12 meses9
Críticas8
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9215Baja (1.8)0.19%—8 sept 2026
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt…
CVE-2026-11739Media (4.9)1.1%—11 ago 2026
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise…
CVE-2026-11736Baja (1.9)0.51%—11 ago 2026
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
CVE-2026-11735Baja (1.9)0.51%—11 ago 2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
CVE-2026-9213Media (6.9)0.68%—9 jun 2026
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
CVE-2026-9210Media (4.9)0.35%—9 jun 2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
CVE-2026-0418Media (4.3)0.24%—9 jun 2026
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
CVE-2026-0417Media (4.3)0.23%—9 jun 2026
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
CVE-2026-0410Baja (1.9)0.22%—9 jun 2026
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
CVE-2024-35517Alta (7.2)15%—11 oct 2024
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
CVE-2021-34983Media (6.5)0.33%—7 may 2024
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected…
CVE-2021-34982Alta (8.8)0.58%—7 may 2024
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple…
CVE-2021-45654Alta (7.5)1.0%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information.
CVE-2021-45643Media (6.5)0.48%—26 dic 2021
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, and XR1000 before 1.0.0.58.
CVE-2021-45622Crítica (9.8)2.4%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74,…
CVE-2021-45621Crítica (9.8)2.0%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX3700 before 1.0.0.94,…
CVE-2021-45620Crítica (9.8)2.0%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, LAX20 before 1.1.6.28,…
CVE-2021-45616Crítica (9.8)2.0%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116,…
CVE-2021-45614Crítica (9.8)2.0%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116,…
CVE-2021-45613Crítica (9.8)2.0%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116,…
CVE-2021-45612Crítica (9.8)2.5%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74,…
CVE-2021-45604Media (4.5)0.37%—26 dic 2021
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D6400 before 1.0.0.102, D8500 before 1.0.3.60, LAX20 before…
CVE-2021-45549Media (6.8)0.63%—26 dic 2021
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 before 1.1.6.122, MR60 before 1.1.6.122, MS60 before 1.1.6.122, R6400v2 before 1.0.4.118,…
CVE-2021-45522Alta (8.8)0.85%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.
CVE-2021-45519Media (6.5)0.44%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
CVE-2021-45518Media (6.5)0.37%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
CVE-2021-45517Media (6.5)0.37%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
CVE-2021-45514Alta (8.8)0.82%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
CVE-2021-45513Crítica (9.6)0.82%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
CVE-2021-45510Alta (8.8)0.52%—26 dic 2021
NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Netgear