Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

1363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.2)0.36%—Netgear Rax30 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware+18/9/202611/9/2026
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the…
AnalizadaBaja (1.8)0.19%—Netgear Xr1000 FirmwareNetgear Xr1000v2 FirmwareNetgear Xr500 Firmware8/9/202611/9/2026
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality…
AnalizadaMedia (4.3)0.23%—Netgear R7000 Firmware11/8/20269/9/2026
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
AnalizadaMedia (4.9)0.91%—Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+2211/8/20269/9/2026
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
AnalizadaMedia (4.9)1.1%—Netgear Ms90 FirmwareNetgear Rax20 FirmwareNetgear Rax200 FirmwareNetgear Rax35 Firmware+2311/8/20269/9/2026
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
AnalizadaMedia (4.3)0.27%—Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+2211/8/20269/9/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
AnalizadaMedia (4.3)0.22%—Netgear Rax20 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 FirmwareNetgear Rax42 Firmware+911/8/20269/9/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
AnalizadaBaja (1.9)0.51%—Netgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 Firmware+1511/8/20269/9/2026
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
AnalizadaBaja (1.9)0.51%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+1611/8/20269/9/2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
AnalizadaBaja (1.1)0.60%—Netgear Mr70 FirmwareNetgear Mr90 FirmwareNetgear Ms70 FirmwareNetgear Ms90 Firmware+1111/8/20269/9/2026
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
AnalizadaBaja (1.1)0.51%—Netgear Rax41 FirmwareNetgear Rax41v2 FirmwareNetgear Rax42 FirmwareNetgear Rax42v2 Firmware+711/8/20269/9/2026
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
AplazadaCrítica (9.8)2.8%—Netgear Tr1200AINetgear Tr3000AINetgear Wr300AINetgear Wr1200AI+531/7/202631/8/2026
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the ipsec_conn interface. This vulnerability allows attackers to execute arbitrary commands as root via a…
AplazadaMedia (4.3)0.24%—Netgear Wax333AI14/7/202615/7/2026
A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connected to the local network to make unauthorized changes to the device's settings
AplazadaMedia (4.7)0.30%—Netgear Nighthawk RAXAI14/7/202615/7/2026
A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged in to the device to run unauthorized commands or code on the router.
AplazadaMedia (4.9)0.15%—Netgear Xr1000AINetgear NighthawkAI14/7/202615/7/2026
A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and certain Nighthawk models that could allow an unauthorized person to remotely access and take control of the device.
AplazadaMedia (5.4)0.26%—Netgear RAXAI14/7/202615/7/2026
A security flaw was found in certain NETGEAR RAX models that could allow a logged-in user to send specially crafted requests to the router and run unauthorized commands. This could enable the user to make unauthorized changes to the router and affect its security and operation.
AplazadaMedia (5.7)0.33%—Netgear OrbiAI14/7/202615/7/2026
A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network connectivity and making the device temporarily unavailable.
AplazadaMedia (6.3)0.25%—Netgear Dgnd3700v1AI14/7/202615/7/2026
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was identified through testing in a controlled research environment using a simulated version of the router's software and has not been confirmed on…
AnalizadaMedia (6.9)0.68%—Netgear Mr70 FirmwareNetgear Ms70 FirmwareNetgear Raxe500 FirmwareNetgear Xr1000 Firmware9/6/202623/7/2026
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
AnalizadaMedia (5.6)0.47%—Netgear Lbr1020 FirmwareNetgear Lbr20 FirmwareNetgear R6700ax FirmwareNetgear R7800 Firmware+189/6/202623/7/2026
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
AnalizadaMedia (5.2)0.39%—Netgear Cax30 FirmwareNetgear Rax30 FirmwareNetgear Rax5 FirmwareNetgear Raxe300 Firmware9/6/202623/7/2026
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
AnalizadaMedia (4.9)0.35%—Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+279/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.9)0.41%—Netgear Rbe970 FirmwareNetgear Rbe971 FirmwareNetgear Rbr860 FirmwareNetgear Rbre950 Firmware+49/6/202623/7/2026
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
AnalizadaMedia (4.6)0.14%—Netgear Rax120 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware9/6/202623/7/2026
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.
AnalizadaMedia (4.4)0.29%—Netgear Jr6150 Firmware9/6/202623/7/2026
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR…