Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Netgear R8000 Firmware | 8/9/2022 | 17/6/2026 | Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'. | |
| Modificada | Alta (8.8) | 1.8% | — | Netgear R6200 FirmwareNetgear R6300 Firmware | 7/9/2022 | 9/7/2026 | NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length… | |
| Modificada | Media (5.3) | 1.3% | — | Netgear Wnap320 Firmware | 17/6/2022 | 17/6/2026 | netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies. | |
| Modificada | Crítica (9.8) | 49% | 💥 Exploit | Netgear Ssl312 Firmware | 13/5/2022 | 17/6/2026 | NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi. | |
| Modificada | Alta (8.8) | 2.9% | — | Netgear R8500 Firmware | 26/3/2022 | 17/6/2026 | NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter. | |
| Modificada | Alta (8.8) | 3.2% | — | Netgear R8500 Firmware | 26/3/2022 | 17/6/2026 | NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi. | |
| Modificada | Alta (8.8) | 2.9% | — | Netgear R8500 Firmware | 26/3/2022 | 17/6/2026 | NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi. | |
| Modificada | Alta (7.8) | 1.1% | — | Netgear Ex6100 FirmwareNetgear Ex6200 FirmwareNetgear Cax80 FirmwareNetgear Dc112a Firmware | 18/3/2022 | 17/6/2026 | A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication. | |
| Modificada | Alta (7.5) | 2.2% | — | Netgear Mbr1517 FirmwareNetgear Wnce3001 FirmwareNetgear Wac104 Firmware | 17/3/2022 | 17/6/2026 | A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device. | |
| Modificada | Media (5.3) | 20% | — | Netgear Wac104 FirmwareNetgear R7450 FirmwareNetgear R6900 FirmwareNetgear R7800 Firmware+1 | 17/3/2022 | 17/6/2026 | A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes firmware version information for the device. | |
| Modificada | Media (6.1) | 0.73% | — | Netgear Wac120 AC Firmware | 4/3/2022 | 17/6/2026 | Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking. | |
| Modificada | Media (6.5) | 0.90% | — | Netgear Xr1000 | 25/1/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP messages. The issue results from a lack of… | |
| Modificada | Alta (8.8) | 3.1% | — | Netgear Ac2100 FirmwareNetgear Ac2400 FirmwareNetgear Ac2600 FirmwareNetgear D7000v1 Firmware+13 | 25/1/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from… | |
| Modificada | Alta (8.8) | 1.4% | — | Netgear R6260 Firmware | 13/1/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setupwizard.cgi page. When parsing the SOAP_LOGIN_TOKEN environment… | |
| Modificada | Alta (8.8) | 1.4% | — | Netgear R6260 Firmware | 13/1/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process… | |
| Modificada | Alta (8.8) | 1.5% | — | Netgear R6260 Firmware | 13/1/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6260 1.1.0.78_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setupwizard.cgi page. A crafted SOAP request can trigger an overflow of a… | |
| Modificada | Alta (8.8) | 1.1% | — | Netgear R7000 Firmware | 13/1/2022 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper… | |
| Modificada | Alta (8.8) | 0.78% | — | Netgear R6700 Firmware | 30/12/2021 | 17/6/2026 | Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracting the configuration using readily available public tools, a user can… | |
| Modificada | Alta (7.5) | 0.59% | — | Netgear R6700 Firmware | 30/12/2021 | 17/6/2026 | Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary configuration file on the device. | |
| Modificada | Media (6.8) | 0.36% | — | Netgear R6700 Firmware | 30/12/2021 | 17/6/2026 | Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection and execute commands as the root user without authentication. | |
| Modificada | Alta (7.5) | 0.59% | — | Netgear R6700 Firmware | 30/12/2021 | 17/6/2026 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be transmitted in cleartext | |
| Modificada | Alta (7.5) | 0.59% | — | Netgear R6700 Firmware | 30/12/2021 | 17/6/2026 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be transmitted in cleartext. | |
| Modificada | Alta (8.8) | 3.2% | — | Netgear R6700 Firmware | 30/12/2021 | 17/6/2026 | Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values. | |
| Modificada | Alta (7.8) | 0.29% | — | Netgear Genie Installer | 30/12/2021 | 17/6/2026 | All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the software is going to be installed may… | |
| Modificada | Media (5.5) | 0.19% | — | Netgear Rax43 Firmware | 30/12/2021 | 17/6/2026 | Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary configuration file on the device. |