Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Netgear D7800 FirmwareNetgear Ex6200 FirmwareNetgear Ex8000 FirmwareNetgear R6220 Firmware+529/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of…
ModificadaMedia (5.9)0.61%—Netgear Rbs750 Firmware21/3/202317/6/2026
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information.
ModificadaAlta (8.8)2.1%—Netgear Rbs750 Firmware21/3/202317/6/2026
A command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.
ModificadaAlta (8.8)2.8%—Netgear Rbs750 Firmware21/3/202317/6/2026
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaAlta (7.2)2.0%—Netgear Rbs750 Firmware21/3/202317/6/2026
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.
ModificadaAlta (7.5)0.63%—Netgear Rax30 Firmware15/3/202317/6/2026
Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A sufficiently large file will cause device resources to be exhausted, resulting in the device…
ModificadaAlta (8.8)0.72%—Netgear Rax30 Firmware15/3/202317/6/2026
When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.
ModificadaCrítica (9.8)0.87%—Netgear Rax30 Firmware14/3/202317/6/2026
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an unauthenticated attacker to gain administrative access to the device's web management interface by resetting the admin password.
ModificadaCrítica (9.8)20%—Netgear Rax30 Firmware10/3/202317/6/2026
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.
ModificadaCrítica (9.8)0.81%—Netgear Rax30 Firmware10/3/202317/6/2026
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.
ModificadaAlta (8.8)0.77%—Netgear Rax30 Firmware10/3/202317/6/2026
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the device.
ModificadaMedia (6.8)0.34%—Netgear Rax30 Firmware10/3/202317/6/2026
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.
ModificadaAlta (8.8)0.27%—Netgear Rax30 Firmware10/3/202317/6/2026
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
ModificadaAlta (7.5)1.0%—Netgear Wndr3700 Firmware15/2/202317/6/2026
A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown processing of the component Web Interface. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)2.8%—Netgear Wndr3700 Firmware15/2/202317/6/2026
A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (7.5)0.88%—Netgear Wndr3700 Firmware15/2/202317/6/2026
A vulnerability was found in Netgear WNDR3700v2 1.0.1.14. It has been rated as problematic. This issue affects some unknown processing of the component Web Management Interface. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)0.58%—Netgear Prosafe Fs726tp Firmware15/2/202317/6/2026
An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.
ModificadaCrítica (9.8)0.68%—Netgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6900p FirmwareNetgear R7000p Firmware+213/2/202317/6/2026
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.
ModificadaAlta (7.4)0.57%—Netgear Wnr612v2 FirmwareNetgear Dgn1000v3 FirmwareNetgear D6100 FirmwareNetgear Wnr1000v2 Firmware+52/2/202317/6/2026
An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the checksum verification.…
ModificadaAlta (7.8)0.45%—Netgear R7000p FirmwareNetgear R6900p FirmwareNetgear R7960p FirmwareNetgear R8000p Firmware+231/1/202317/6/2026
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.
ModificadaMedia (6.1)0.76%💥 PoCNetgear Ac1200 R6220 Firmware26/1/202317/6/2026
The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerability using a specially crafted URL. This affects firmware versions:…
ModificadaCrítica (9.8)0.94%—Netgear Rax40 FirmwareNetgear Rax35 FirmwareNetgear R6400v2 FirmwareNetgear R6700v3 Firmware+530/12/202217/6/2026
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152, R7000 before 1.0.11.136, R7960P before 1.4.4.94, and R8000P before…
ModificadaAlta (8.1)0.88%—Netgear Xwn5001 Firmware20/12/202217/6/2026
An exploitable firmware modification vulnerability was discovered on the Netgear XWN5001 Powerline 500 WiFi Access Point. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of…
ModificadaAlta (8.1)0.41%—Netgear Wnr2000 Firmware20/12/202217/6/2026
An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects…
ModificadaMedia (4.8)0.27%—Netgear Wnr2000 Firmware20/12/202217/6/2026
An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware image during the firmware update process.