« Back to list

Netgear

Netgear R7000 Firmware: vulnerabilities and CVEs

Netgear R7000 Firmware has 141 published vulnerabilities, 7 of them in the last 12 months. 22 are rated critical and 1 are listed by CISA as actively exploited.

CVEs141
Last 12 months7
Critical22
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2016-6277High (8.8)100%⚠ Active exploitationDec 14, 2016
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-9214Medium (4.3)0.23%—Aug 11, 2026
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11735Low (1.9)0.51%—Aug 11, 2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
CVE-2026-9210Medium (4.9)0.35%—Jun 9, 2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
CVE-2026-0417Medium (4.3)0.23%—Jun 9, 2026
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
CVE-2026-0410Low (1.9)0.22%—Jun 9, 2026
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
CVE-2022-40620High (7.7)0.30%—Jan 28, 2026
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker…
CVE-2022-40619High (7.7)2.5%—Jan 28, 2026
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command…
CVE-2025-44650High (7.5)0.54%—Jul 21, 2025
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.
CVE-2024-35520Medium (6.8)9.6%—Oct 14, 2024
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2021-34983Medium (6.5)0.33%—May 7, 2024
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected…
CVE-2021-34982High (8.8)0.58%—May 7, 2024
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple…
CVE-2024-1431Medium (6.5)0.53%—Feb 11, 2024
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface.…
CVE-2024-1430Medium (5.3)0.63%—Feb 11, 2024
A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web…
CVE-2023-36187Critical (9.8)1.1%—Sep 1, 2023
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
CVE-2022-27647High (8)1.5%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability,…
CVE-2022-27646High (8.8)1.4%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability,…
CVE-2022-27645High (8.8)1.3%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists…
CVE-2022-27644High (8.8)0.34%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to…
CVE-2022-27643High (8.8)25%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The…
CVE-2022-27642High (8.8)0.88%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The…
CVE-2022-27641High (8.8)1.2%—Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The…
CVE-2022-48196Critical (9.8)0.94%—Dec 30, 2022
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before…
CVE-2022-37235Critical (9.8)1.2%—Sep 23, 2022
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat
CVE-2022-37234High (7.8)0.54%—Sep 22, 2022
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.
CVE-2021-34977High (8.8)1.1%—Jan 13, 2022
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The…
CVE-2021-45679High (7.2)0.96%—Dec 26, 2021
Certain NETGEAR devices are affected by privilege escalation. This affects R6900P before 1.3.3.140, R7000 before 1.0.11.126, R7000P before 1.3.3.140, and RS400 before 1.5.1.80.
CVE-2021-45674Medium (4.8)0.42%—Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX15 before 1.0.2.82, RAX20 before 1.0.2.82, RAX200 before 1.0.3.106, RAX75 before…
CVE-2021-45673Medium (5.4)0.48%—Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RAX200 before 1.0.3.106, R7000P before 1.3.3.140, RAX80 before 1.0.3.106, R6900P…
CVE-2021-45670Medium (4.8)0.42%—Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7500 before 1.0.0.72, R7000 before…
CVE-2021-45664Medium (4.8)0.56%—Dec 26, 2021
NETGEAR R7000 devices before 1.0.11.126 are affected by stored XSS.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter3
  2. T1190 Exploit Public-Facing Application2
  3. T1203 Exploitation for Client Execution1
  4. T1499.004 Application or System Exploitation1
  5. T1557 Adversary-in-the-Middle1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Netgear