Netgear
Netgear Xr1000 Firmware: vulnerabilidades y CVE
Netgear Xr1000 Firmware tiene 30 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses9
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9215 | Baja (1.8) | 0.19% | — | 8 sept 2026 | A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt… |
| CVE-2026-11739 | Media (4.9) | 1.1% | — | 11 ago 2026 | A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise… |
| CVE-2026-11736 | Baja (1.9) | 0.51% | — | 11 ago 2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. |
| CVE-2026-11735 | Baja (1.9) | 0.51% | — | 11 ago 2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. |
| CVE-2026-9213 | Media (6.9) | 0.68% | — | 9 jun 2026 | A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device. |
| CVE-2026-9210 | Media (4.9) | 0.35% | — | 9 jun 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality. |
| CVE-2026-0418 | Media (4.3) | 0.24% | — | 9 jun 2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system. |
| CVE-2026-0417 | Media (4.3) | 0.23% | — | 9 jun 2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity. |
| CVE-2026-0410 | Baja (1.9) | 0.22% | — | 9 jun 2026 | Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality. |
| CVE-2024-35517 | Alta (7.2) | 15% | — | 11 oct 2024 | Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter. |
| CVE-2021-34983 | Media (6.5) | 0.33% | — | 7 may 2024 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected… |
| CVE-2021-34982 | Alta (8.8) | 0.58% | — | 7 may 2024 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple… |
| CVE-2021-45654 | Alta (7.5) | 1.0% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information. |
| CVE-2021-45643 | Media (6.5) | 0.48% | — | 26 dic 2021 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, and XR1000 before 1.0.0.58. |
| CVE-2021-45622 | Crítica (9.8) | 2.4% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74,… |
| CVE-2021-45621 | Crítica (9.8) | 2.0% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX3700 before 1.0.0.94,… |
| CVE-2021-45620 | Crítica (9.8) | 2.0% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, LAX20 before 1.1.6.28,… |
| CVE-2021-45616 | Crítica (9.8) | 2.0% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116,… |
| CVE-2021-45614 | Crítica (9.8) | 2.0% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116,… |
| CVE-2021-45613 | Crítica (9.8) | 2.0% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116,… |
| CVE-2021-45612 | Crítica (9.8) | 2.5% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74,… |
| CVE-2021-45604 | Media (4.5) | 0.37% | — | 26 dic 2021 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D6400 before 1.0.0.102, D8500 before 1.0.3.60, LAX20 before… |
| CVE-2021-45549 | Media (6.8) | 0.63% | — | 26 dic 2021 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 before 1.1.6.122, MR60 before 1.1.6.122, MS60 before 1.1.6.122, R6400v2 before 1.0.4.118,… |
| CVE-2021-45522 | Alta (8.8) | 0.85% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password. |
| CVE-2021-45519 | Media (6.5) | 0.44% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service. |
| CVE-2021-45518 | Media (6.5) | 0.37% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service. |
| CVE-2021-45517 | Media (6.5) | 0.37% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service. |
| CVE-2021-45514 | Alta (8.8) | 0.82% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker. |
| CVE-2021-45513 | Crítica (9.6) | 0.82% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker. |
| CVE-2021-45510 | Alta (8.8) | 0.52% | — | 26 dic 2021 | NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.