Netgear
Netgear R7000 Firmware: vulnerabilities and CVEs
Netgear R7000 Firmware has 141 published vulnerabilities, 7 of them in the last 12 months. 22 are rated critical and 1 are listed by CISA as actively exploited.
CVEs141
Last 12 months7
Critical22
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6277 | High (8.8) | 100% | ⚠ Active exploitation | Dec 14, 2016 | NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9214 | Medium (4.3) | 0.23% | — | Aug 11, 2026 | Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. |
| CVE-2026-11735 | Low (1.9) | 0.51% | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. |
| CVE-2026-9210 | Medium (4.9) | 0.35% | — | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. |
| CVE-2026-0417 | Medium (4.3) | 0.23% | — | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. |
| CVE-2026-0410 | Low (1.9) | 0.22% | — | Jun 9, 2026 | Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. |
| CVE-2022-40620 | High (7.7) | 0.30% | — | Jan 28, 2026 | FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker… |
| CVE-2022-40619 | High (7.7) | 2.5% | — | Jan 28, 2026 | FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command… |
| CVE-2025-44650 | High (7.5) | 0.54% | — | Jul 21, 2025 | In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected. |
| CVE-2024-35520 | Medium (6.8) | 9.6% | — | Oct 14, 2024 | Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter. |
| CVE-2021-34983 | Medium (6.5) | 0.33% | — | May 7, 2024 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected… |
| CVE-2021-34982 | High (8.8) | 0.58% | — | May 7, 2024 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple… |
| CVE-2024-1431 | Medium (6.5) | 0.53% | — | Feb 11, 2024 | A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface.… |
| CVE-2024-1430 | Medium (5.3) | 0.63% | — | Feb 11, 2024 | A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web… |
| CVE-2023-36187 | Critical (9.8) | 1.1% | — | Sep 1, 2023 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd. |
| CVE-2022-27647 | High (8) | 1.5% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability,… |
| CVE-2022-27646 | High (8.8) | 1.4% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability,… |
| CVE-2022-27645 | High (8.8) | 1.3% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… |
| CVE-2022-27644 | High (8.8) | 0.34% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to… |
| CVE-2022-27643 | High (8.8) | 25% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2022-27642 | High (8.8) | 0.88% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2022-27641 | High (8.8) | 1.2% | — | Mar 29, 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2022-48196 | Critical (9.8) | 0.94% | — | Dec 30, 2022 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before… |
| CVE-2022-37235 | Critical (9.8) | 1.2% | — | Sep 23, 2022 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat |
| CVE-2022-37234 | High (7.8) | 0.54% | — | Sep 22, 2022 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy. |
| CVE-2021-34977 | High (8.8) | 1.1% | — | Jan 13, 2022 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2021-45679 | High (7.2) | 0.96% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by privilege escalation. This affects R6900P before 1.3.3.140, R7000 before 1.0.11.126, R7000P before 1.3.3.140, and RS400 before 1.5.1.80. |
| CVE-2021-45674 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before… |
| CVE-2021-45673 | Medium (5.4) | 0.48% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P… |
| CVE-2021-45670 | Medium (4.8) | 0.42% | — | Dec 26, 2021 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before… |
| CVE-2021-45664 | Medium (4.8) | 0.56% | — | Dec 26, 2021 | NETGEAR R7000 devices before 1.0.11.126 are affected by stored XSS. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.