Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.1%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+3914/4/202117/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service…
ModificadaAlta (8.8)1.1%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+3914/4/202117/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the vendor_specific DHCP opcode. The issue results from the…
ModificadaAlta (8.8)0.73%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+3914/4/202117/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from a fallback to a insecure protocol to…
ModificadaAlta (8.8)1.1%—Netgear R6700 FirmwareNetgear R6400 FirmwareNetgear R7000 FirmwareNetgear R6900p Firmware+7623/3/202117/6/2026
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7000 before 1.0.11.106, R6900P before 1.3.2.124, R7000P before 1.3.2.124, R7900 before 1.0.4.26, R7850 before 1.0.5.60, R8000 before 1.0.4.58, RS400 before 1.5.0.48, R6400…
ModificadaMedia (6.5)0.32%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+395/3/202117/6/2026
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via FTP. The issue…
ModificadaAlta (8.8)0.96%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+395/3/202117/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of…
ModificadaAlta (8.8)1.4%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+395/3/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the refresh_status.aspx endpoint. The issue results from a lack of authentication…
ModificadaAlta (8.8)0.52%—Netgear Br200 FirmwareNetgear Br500 FirmwareNetgear D7800 FirmwareNetgear Ex6100v2 Firmware+395/3/202117/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker…
ModificadaAlta (8.8)2.0%—Netgear Cbk40 FirmwareNetgear Cbk43 FirmwareNetgear Cbr40 FirmwareNetgear Ex6200 Firmware+3512/2/202117/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name option in a DHCP request can trigger…