Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.95%—Netgear Wnr614 Firmware3/6/202517/6/2026
A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL Handler. The manipulation with the input %00currentsetting.htm leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaAlta (8.2)0.29%—Netgear Wnr614 Firmware7/6/202417/6/2026
An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's pin.
AnalizadaAlta (8.8)0.35%—Netgear Wnr614 Firmware7/6/202417/6/2026
Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
AnalizadaAlta (8.1)0.40%—Netgear Wnr614 Firmware7/6/202417/6/2026
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
ModificadaMedia (4.8)0.27%—Netgear Wnr614 Firmware7/6/202417/6/2026
Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.
AnalizadaAlta (8.8)0.57%—Netgear Wnr614 Firmware7/6/202417/6/2026
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
AnalizadaMedia (4)0.34%—Netgear Wnr614 Firmware6/6/202417/6/2026
Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.
ModificadaAlta (7.5)1.0%—Netgear Jnr1010 FirmwareNetgear Jwnr2000 FirmwareNetgear Jwnr2010 FirmwareNetgear R6220 Firmware+528/4/202017/6/2026
Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR614 before 2017-01-06, WNR618 before 2017-01-06, JWNR2000v5 before 2017-01-06, WNR2020 before 2017-01-06, JWNR2010v5 before 2017-01-06, WNR1000v4 before 2017-01-06, WNR2020v2 before 2017-01-06, R6220…
ModificadaAlta (8.8)0.46%—Netgear R6050 FirmwareNetgear Jr6150 FirmwareNetgear Pr2000 FirmwareNetgear R6220 Firmware+921/4/202017/6/2026
Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050 before 1.1.0.40, WNR614 before 1.1.0.40,…
ModificadaAlta (8.8)0.57%—Netgear D6200 FirmwareNetgear D7000 FirmwareNetgear R6020 FirmwareNetgear R6080 Firmware+416/4/202017/6/2026
Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.30, D7000 before 1.0.1.66, R6020 before 1.0.0.34, R6080 before 1.0.0.34, R6120 before 1.0.0.44, R6220 before 1.1.0.68, WNR2020 before 1.1.0.54, and WNR614 before 1.1.0.54.
AnalizadaCrítica (9.8)83%⚠ Explotación activaNetgear D6100 FirmwareNetgear D7000 FirmwareNetgear D7800 FirmwareNetgear Jnr1010v2 Firmware+2430/1/201717/6/2026
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.