Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.41% | — | Netgear D6100 FirmwareNetgear D7000 FirmwareNetgear D7800 FirmwareNetgear Jnr1010 Firmware+10 | 22/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108, R7500v2 before 1.0.3.10, WNDR4300v1 before… | |
| Modificada | Media (6.7) | 0.64% | — | Netgear D3600 FirmwareNetgear D6000 FirmwareNetgear D6100 FirmwareNetgear D6200 Firmware+49 | 22/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D6200 before 1.1.00.24, D6220 before 1.0.0.32, D6400 before 1.0.0.66, D7000 before 1.0.1.52, D7000v2 before 1.0.0.44, D7800 before 1.0.1.30, D8500 before… | |
| Modificada | Alta (8.8) | 0.46% | — | Netgear R6050 FirmwareNetgear Jr6150 FirmwareNetgear Pr2000 FirmwareNetgear R6220 Firmware+9 | 21/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050 before 1.1.0.40, WNR614 before 1.1.0.40,… | |
| Modificada | Media (5.4) | 0.54% | — | Netgear D6100 FirmwareNetgear D7800 FirmwareNetgear Jnr1010 FirmwareNetgear Jwnr2010 Firmware+21 | 16/4/2020 | 17/6/2026 | Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.34, JNR1010v2 before 1.1.0.50, JWNR2010v5 before 1.1.0.50, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, R6020 before 1.0.0.30, R6080 before 1.0.0.30, R6100 before 1.0.1.16, R6120 before… | |
| Modificada | Crítica (9.8) | 1.3% | — | Netgear Wnr1000 Firmware | 2/3/2020 | 17/6/2026 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a… | |
| Modificada | Crítica (9.8) | 2.1% | — | Netgear Wnr1000 Firmware | 2/3/2020 | 17/6/2026 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter. | |
| Modificada | Alta (8.8) | 0.46% | — | Netgear Wnr1000 Firmware | 2/3/2020 | 17/6/2026 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI. | |
| Modificada | Media (6.1) | 0.67% | — | Netgear Wnr1000 Firmware | 2/3/2020 | 17/6/2026 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language. | |
| Modificada | Crítica (9.8) | 4.8% | — | Netgear Wnr1000 Firmware | 29/1/2020 | 16/6/2026 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. | |
| Modificada | Crítica (9.8) | 4.8% | — | Netgear Wnr1000 Firmware | 29/1/2020 | 16/6/2026 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". | |
| Modificada | Alta (8.1) | 1.7% | — | Netgear Ac1450 FirmwareNetgear D8500 FirmwareNetgear Dc112a FirmwareNetgear Jndr3000 Firmware+29 | 9/10/2019 | 17/6/2026 | Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200,… |