Netgear
Netgear Rax40 Firmware: vulnerabilidades y CVE
Netgear Rax40 Firmware tiene 26 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9216 | Baja (1.2) | 0.36% | — | 8 sept 2026 | An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no… |
| CVE-2026-0420 | Media (4.6) | 0.14% | — | 9 jun 2026 | An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the… |
| CVE-2023-27358 | Alta (8.8) | 0.88% | — | 3 may 2024 | NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers.… |
| CVE-2022-27647 | Alta (8) | 1.5% | — | 29 mar 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability,… |
| CVE-2022-27645 | Alta (8.8) | 1.3% | — | 29 mar 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… |
| CVE-2022-27642 | Alta (8.8) | 0.88% | — | 29 mar 2023 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The… |
| CVE-2022-48196 | Crítica (9.8) | 0.94% | — | 30 dic 2022 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before… |
| CVE-2021-45672 | Media (4.8) | 0.36% | — | 26 dic 2021 | Certain NETGEAR devices are affected by Stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6220 before 1.1.0.110, R6230 before… |
| CVE-2021-45604 | Media (4.5) | 0.37% | — | 26 dic 2021 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D6400 before 1.0.0.102, D8500 before 1.0.3.60, LAX20 before… |
| CVE-2021-45549 | Media (6.8) | 0.63% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 before 1.1.6.122, MR60 before 1.1.6.122, MS60 before 1.1.6.122, R6400v2 before 1.0.4.118,… |
| CVE-2021-45493 | Alta (7.5) | 0.77% | — | 26 dic 2021 | Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102. |
| CVE-2021-41449 | Alta (7.1) | 1.6% | — | 9 dic 2021 | A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden… |
| CVE-2021-38537 | Media (4.8) | 0.36% | — | 11 ago 2021 | Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before… |
| CVE-2021-38536 | Media (4.8) | 0.46% | — | 11 ago 2021 | Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before… |
| CVE-2021-38535 | Media (4.8) | 0.46% | — | 11 ago 2021 | Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6700v2 before… |
| CVE-2021-38533 | Media (5.4) | 0.47% | — | 11 ago 2021 | NETGEAR RAX40 devices before 1.0.3.64 are affected by stored XSS. |
| CVE-2021-38526 | Alta (7.5) | 1.0% | — | 11 ago 2021 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX35 before 1.0.3.94, RAX38 before 1.0.3.94, and RAX40 before 1.0.3.94. |
| CVE-2020-35800 | Crítica (9.4) | 1.6% | — | 30 dic 2020 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10,… |
| CVE-2020-26898 | Alta (8.8) | 0.60% | — | 9 oct 2020 | NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings. |
| CVE-2019-20647 | Media (5.7) | 0.49% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.64 are affected by denial of service. |
| CVE-2019-20646 | Crítica (9.8) | 1.3% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of administrative credentials. |
| CVE-2019-20645 | Media (4.8) | 0.49% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS. |
| CVE-2019-20644 | Media (4.8) | 0.48% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS. |
| CVE-2019-20643 | Alta (7.5) | 0.83% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information. |
| CVE-2019-20642 | Alta (8) | 0.54% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass. |
| CVE-2019-20641 | Alta (8.8) | 0.83% | — | 15 abr 2020 | NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level. |