Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

56 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)0.91%—Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+2211/8/20269/9/2026
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
AnalizadaMedia (4.9)1.1%—Netgear Ms90 FirmwareNetgear Rax20 FirmwareNetgear Rax200 FirmwareNetgear Rax35 Firmware+2311/8/20269/9/2026
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
AnalizadaMedia (4.3)0.27%—Netgear Be9300 FirmwareNetgear Mr60 FirmwareNetgear Ms60 FirmwareNetgear R6700ax Firmware+2211/8/20269/9/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
AnalizadaMedia (4.3)0.22%—Netgear Rax20 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 FirmwareNetgear Rax42 Firmware+911/8/20269/9/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
AnalizadaBaja (1.9)0.51%—Netgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 FirmwareNetgear Rax41v2 Firmware+1511/8/20269/9/2026
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
AnalizadaBaja (1.9)0.51%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+1611/8/20269/9/2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
AnalizadaBaja (1.1)0.60%—Netgear Mr70 FirmwareNetgear Mr90 FirmwareNetgear Ms70 FirmwareNetgear Ms90 Firmware+1111/8/20269/9/2026
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
AnalizadaBaja (1.1)0.51%—Netgear Rax41 FirmwareNetgear Rax41v2 FirmwareNetgear Rax42 FirmwareNetgear Rax42v2 Firmware+711/8/20269/9/2026
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
AnalizadaMedia (4.9)0.35%—Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+279/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.3)0.24%—Netgear Cbr750 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 FirmwareNetgear Mr60 Firmware+319/6/202623/7/2026
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
AnalizadaMedia (4.3)0.23%—Netgear Mr60 FirmwareNetgear Mr70 FirmwareNetgear Mr80 FirmwareNetgear Ms60 Firmware+239/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
AnalizadaBaja (1.9)0.22%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+159/6/202623/7/2026
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
AnalizadaMedia (4.4)0.29%—Netgear Rs700 FirmwareNetgear Rax54sv2 FirmwareNetgear Rax45v2 FirmwareNetgear Rax41v2 Firmware+149/12/202530/9/2026
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through…
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.
AnalizadaCrítica (9.8)1.2%—Netgear Rax50 Firmware5/5/202517/6/2026
NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
AnalizadaMedia (6.5)0.33%—Netgear Xr1000 FirmwareNetgear Xr300 FirmwareNetgear D6220 FirmwareNetgear D6400 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (8.8)0.58%—Netgear Dc112a FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (8.8)1.00%—Netgear Rax50 Firmware3/5/202417/6/2026
NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this…
ModificadaAlta (8)1.5%—Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+2929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling…
ModificadaAlta (8.8)1.3%—Netgear Lax20 FirmwareNetgear R6400 FirmwareNetgear R6700 FirmwareNetgear R7000 Firmware+1929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing…