Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.67%—Netgear Wnr854t Firmware31/3/202517/6/2026
Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program…
AnalizadaCrítica (9.8)0.78%—Netgear Wnr854t Firmware31/3/202517/6/2026
Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.
AnalizadaCrítica (9.8)2.5%—Netgear Wnr854t Firmware31/3/202517/6/2026
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping…
AnalizadaCrítica (9.8)1.1%—Netgear Wnr854t Firmware31/3/202517/6/2026
Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.
AnalizadaCrítica (9.8)2.5%—Netgear Wnr854t Firmware31/3/202517/6/2026
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.
AnalizadaCrítica (9.8)1.7%—Netgear Wnr854t Firmware31/3/202517/6/2026
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.
AnalizadaCrítica (9.8)1.7%—Netgear Wnr854t Firmware31/3/202517/6/2026
Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.
AnalizadaCrítica (9.8)0.68%—Netgear Wnr854t Firmware31/3/202517/6/2026
In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.
AnalizadaCrítica (9.8)13%—Netgear Dc112a Firmware28/3/202517/6/2026
Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.
AnalizadaMedia (6.4)0.30%—Netgear C7800 Firmware18/2/202517/6/2026
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transport security by…
AnalizadaAlta (8.8)2.1%💥 ExploitNetgear Dgn2200 Firmware18/2/202517/6/2026
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
AplazadaAlta (8.1)0.69%—Netgear Xr1000AINetgear Xr1000v2AINetgear Xr500AI5/2/202517/6/2026
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
AplazadaAlta (7.2)1.1%—Netgear Fvs336gv2AINetgear Fvs336gv3AI4/2/202517/6/2026
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands.
ModificadaCrítica (9.8)30%💥 ExploitNetgear Dgn1000 Firmware10/1/202517/6/2026
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpoint. This vulnerability has been observed to be exploited in the wild since at…
AnalizadaMedia (6.9)0.89%—Netgear R6900p FirmwareNetgear R7000p Firmware27/12/202417/6/2026
A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the component HTTP Header Handler. The manipulation of the argument Host leads to buffer overflow. The attack can be launched remotely. The exploit has been…
AplazadaAlta (7.1)0.81%—Netgear R6900AI4/12/202417/6/2026
A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file upgrade_check.cgi of the component HTTP Header Handler. The manipulation of the argument Content-Length leads to buffer overflow. The attack can be…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware22/11/202417/6/2026
NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within…
AnalizadaAlta (7.5)0.57%—Netgear Rax30 Firmware22/11/202417/6/2026
NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific…
AnalizadaMedia (5.7)0.30%—Netgear R7000p Firmware5/11/202417/6/2026
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AnalizadaMedia (5.7)0.31%—Netgear R7000p Firmware5/11/202417/6/2026
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AnalizadaMedia (5.7)0.31%—Netgear R7000p Firmware5/11/202417/6/2026
Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AnalizadaMedia (5.7)0.31%—Netgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware5/11/202417/6/2026
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AnalizadaMedia (5.7)0.31%—Netgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware5/11/202417/6/2026
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AnalizadaMedia (5.7)0.31%—Netgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware5/11/202417/6/2026
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AnalizadaMedia (5.7)0.31%—Netgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware5/11/202417/6/2026
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.