Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.24% | — | Netgear Cbr750 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 FirmwareNetgear Mr60 Firmware+31 | 9/6/2026 | 23/7/2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. | |
| Analizada | Media (4.3) | 0.23% | — | Netgear Mr60 FirmwareNetgear Mr70 FirmwareNetgear Mr80 FirmwareNetgear Ms60 Firmware+23 | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. | |
| Analizada | Media (4.3) | 0.18% | — | Netgear Raxe450 FirmwareNetgear Raxe500 Firmware | 9/6/2026 | 23/7/2026 | An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or… | |
| Analizada | Media (4.3) | 0.23% | — | Netgear Rbe970 FirmwareNetgear Rbr750 FirmwareNetgear Rbr840 FirmwareNetgear Rbr850 Firmware+9 | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analizada | Media (4.3) | 0.17% | — | Netgear Rbe970 Firmware | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analizada | Media (4.3) | 0.32% | — | Netgear Rbe370 FirmwareNetgear Rbe770 FirmwareNetgear Rbr750 FirmwareNetgear Rbr840 Firmware+10 | 9/6/2026 | 23/7/2026 | A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analizada | Media (4.3) | 0.15% | — | Netgear Jr6150 Firmware | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no… | |
| Analizada | Media (4.2) | 0.28% | — | Netgear Rbe970 FirmwareNetgear Rbr350 FirmwareNetgear Rbr760 FirmwareNetgear Rbs350 Firmware+1 | 9/6/2026 | 23/7/2026 | An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this… | |
| Analizada | Baja (1.9) | 0.22% | — | Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+15 | 9/6/2026 | 23/7/2026 | Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. | |
| Analizada | Media (4.8) | 0.26% | — | Netgear Rbe370 FirmwareNetgear Rbe371 FirmwareNetgear Rbe372 FirmwareNetgear Rbe374 Firmware | 9/6/2026 | 23/7/2026 | A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7. | |
| Aplazada | Alta (8.1) | 1.4% | — | Netgear GenieAI | 11/5/2026 | 17/6/2026 | Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/server.js when a user reads from an external FORGE_BASE_URL. | |
| Aplazada | Alta (8.7) | 0.24% | — | NetgearAI | 30/1/2026 | 17/6/2026 | Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box. | |
| Analizada | Alta (7.7) | 0.30% | — | Netgear Rbr20 FirmwareNetgear R6230 FirmwareNetgear R6260 FirmwareNetgear R7000 Firmware+6 | 28/1/2026 | 17/6/2026 | FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a malicious update… | |
| Analizada | Alta (7.7) | 2.5% | — | Netgear Rbr20 FirmwareNetgear R6230 FirmwareNetgear R6260 FirmwareNetgear R7000 Firmware+6 | 28/1/2026 | 17/6/2026 | FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260… | |
| Analizada | Media (6.1) | 0.25% | — | Netgear Ex2800 FirmwareNetgear Ex3110 FirmwareNetgear Ex5000 FirmwareNetgear Ex6110 Firmware | 13/1/2026 | 17/6/2026 | A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI. | |
| Analizada | Media (6.1) | 0.25% | — | Netgear Ex5000 FirmwareNetgear Ex3110 FirmwareNetgear Ex6110 FirmwareNetgear Ex2800 Firmware | 13/1/2026 | 17/6/2026 | An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin panel. | |
| Analizada | Media (6.1) | 0.24% | — | Netgear Xr1000v2 Firmware | 13/1/2026 | 17/6/2026 | An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN to execute OS command injections. | |
| Analizada | Media (6.1) | 0.37% | — | Netgear Cbr750 FirmwareNetgear Nbr750 FirmwareNetgear Rbe370 FirmwareNetgear Rbe371 Firmware+21 | 13/1/2026 | 17/6/2026 | An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin. | |
| Analizada | Media (4.8) | 1.2% | — | Netgear Rbr750 FirmwareNetgear Rbr840 FirmwareNetgear Rbr850 FirmwareNetgear Rbr860 Firmware+8 | 13/1/2026 | 17/6/2026 | An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default. | |
| Analizada | Baja (1.1) | 0.32% | — | Netgear Rbe971 FirmwareNetgear Rbe970 FirmwareNetgear Rbr750 FirmwareNetgear Rbr850 Firmware+6 | 13/1/2026 | 17/6/2026 | An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections. | |
| Analizada | Crítica (9.8) | 1.2% | — | Netgear Ex8000 Firmware | 23/12/2025 | 17/6/2026 | Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. | |
| Analizada | Media (6.5) | 0.90% | — | Netgear Ex8000 Firmware | 23/12/2025 | 17/6/2026 | Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function. | |
| Modificada | Baja (1.1) | 1.1% | — | Netgear R7000p Firmware | 9/12/2025 | 26/8/2026 | An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There… | |
| Analizada | Media (5) | 0.20% | — | Netgear C6230 FirmwareNetgear C6220 Firmware | 9/12/2025 | 17/6/2026 | Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users reboot the router. | |
| Analizada | Media (4.4) | 0.29% | — | Netgear Rs700 FirmwareNetgear Rax54sv2 FirmwareNetgear Rax45v2 FirmwareNetgear Rax41v2 Firmware+14 | 9/12/2025 | 7/10/2026 | A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through… |