Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.2)0.36%—Netgear Rax30 FirmwareNetgear Rax35 FirmwareNetgear Rax38 FirmwareNetgear Rax40 Firmware+18/9/202611/9/2026
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the…
AnalizadaMedia (4.9)0.91%—Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+2211/8/20269/9/2026
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
AnalizadaMedia (4.3)0.27%—Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+2211/8/20269/9/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
AnalizadaMedia (5.2)0.39%—Netgear Cax30 FirmwareNetgear Rax30 FirmwareNetgear Rax5 FirmwareNetgear Raxe300 Firmware9/6/202623/7/2026
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
AnalizadaMedia (5.2)0.16%—Netgear Rax30 FirmwareNetgear Raxe300 Firmware11/11/202517/6/2026
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) allows attackers with the ability to intercept and tamper traffic destined to the device to execute arbitrary commands on the device. Devices…
AnalizadaAlta (7.5)0.57%—Netgear Rax30 Firmware21/7/202517/6/2026
In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.
AnalizadaCrítica (9.8)1.0%—Netgear Rax30 Firmware21/7/202517/6/2026
In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware22/11/202417/6/2026
NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within…
AnalizadaAlta (7.5)0.57%—Netgear Rax30 Firmware22/11/202417/6/2026
NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 DHCP Server Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DHCP…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service.…
AnalizadaMedia (6.8)0.83%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 Telnet CLI passwd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaAlta (8.8)1.3%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of UPnP…
AnalizadaAlta (8.8)0.90%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 cmsCli_authenticate Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists…
AnalizadaMedia (6.3)0.45%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the system…
AnalizadaMedia (4.6)0.65%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically present attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaMedia (5.7)0.34%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaAlta (8.8)0.78%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaAlta (8.8)0.78%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within…
AnalizadaAlta (8)1.4%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can…
AnalizadaAlta (8)0.86%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 rex_cgi JSON Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (8.8)0.45%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 lighttpd Misconfiguration Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the…
AnalizadaAlta (8.8)0.88%—Netgear Rax30 FirmwareNetgear Raxe300 FirmwareNetgear Rax40 FirmwareNetgear Rax35 Firmware+13/5/202417/6/2026
NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…
AnalizadaMedia (6.5)0.57%—Netgear Rax30 Firmware3/5/202417/6/2026
NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaAlta (8)1.2%—Netgear Rax30 FirmwareNetgear Raxe300 Firmware3/5/202417/6/2026
NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be…