Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.35% | — | Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+27 | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. | |
| Analizada | Media (4.3) | 0.23% | — | Netgear Mr60 FirmwareNetgear Mr70 FirmwareNetgear Mr80 FirmwareNetgear Ms60 Firmware+23 | 9/6/2026 | 23/7/2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. | |
| Analizada | Alta (8) | 1.0% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Alta (8) | 1.0% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Alta (8) | 1.0% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Alta (8) | 1.6% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Media (5.7) | 0.41% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted… | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at bsw_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_pri_dns parameter at ipv6_fix.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Alta (8) | 0.96% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component ap_mode.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Alta (8) | 0.96% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Alta (8) | 0.82% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 FirmwareNetgear R7000p Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted… | |
| Analizada | Media (5.7) | 0.31% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.74% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.40% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.40% | — | Netgear R8500 FirmwareNetgear Xr300 FirmwareNetgear R7000p FirmwareNetgear R6400v2 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Analizada | Media (5.7) | 0.30% | — | Netgear R8500 Firmware | 5/11/2024 | 17/6/2026 | Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. |