Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.23%—Netgear R7000 Firmware11/8/20269/9/2026
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
AnalizadaBaja (1.9)0.51%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+1611/8/20269/9/2026
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
AnalizadaMedia (4.9)0.35%—Netgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 FirmwareNetgear Ex6130 Firmware+279/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
AnalizadaMedia (4.3)0.23%—Netgear Mr60 FirmwareNetgear Mr70 FirmwareNetgear Mr80 FirmwareNetgear Ms60 Firmware+239/6/202623/7/2026
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
AnalizadaBaja (1.9)0.22%—Netgear R7000 FirmwareNetgear Rax20 FirmwareNetgear Rax35v2 FirmwareNetgear Rax41 Firmware+159/6/202623/7/2026
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
AnalizadaAlta (7.7)0.30%—Netgear Rbr20 FirmwareNetgear R6230 FirmwareNetgear R6260 FirmwareNetgear R7000 Firmware+628/1/202617/6/2026
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a malicious update…
AnalizadaAlta (7.7)2.5%—Netgear Rbr20 FirmwareNetgear R6230 FirmwareNetgear R6260 FirmwareNetgear R7000 Firmware+628/1/202617/6/2026
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260…
AnalizadaAlta (7.5)0.54%—Netgear R7000 FirmwareNetgear Eax80 Firmware21/7/202517/6/2026
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.
AnalizadaMedia (6.8)9.6%—Netgear R7000 Firmware14/10/202417/6/2026
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
AnalizadaMedia (6.5)0.33%—Netgear Xr1000 FirmwareNetgear Xr300 FirmwareNetgear D6220 FirmwareNetgear D6400 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (8.8)0.58%—Netgear Dc112a FirmwareNetgear Ex3700 FirmwareNetgear Ex3800 FirmwareNetgear Ex6120 Firmware+487/5/202417/6/2026
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists…
ModificadaMedia (6.5)0.53%—Netgear R7000 Firmware11/2/202417/6/2026
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may…
ModificadaMedia (5.3)0.63%—Netgear R7000 Firmware11/2/202417/6/2026
A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to…
ModificadaCrítica (9.8)1.1%—Netgear Cbr40 FirmwareNetgear Lax20 FirmwareNetgear Mk62 FirmwareNetgear Mr60 Firmware+111/9/202317/6/2026
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
ModificadaAlta (8)1.5%—Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+2929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling…
ModificadaAlta (8.8)1.4%—Netgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900p FirmwareNetgear R7000 Firmware+2029/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled…
ModificadaAlta (8.8)1.3%—Netgear Lax20 FirmwareNetgear R6400 FirmwareNetgear R6700 FirmwareNetgear R7000 Firmware+1929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing…
ModificadaAlta (8.8)0.34%—Netgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900p FirmwareNetgear R7000 Firmware+2029/3/202317/6/2026
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue…
ModificadaAlta (8.8)25%—Netgear R6400 FirmwareNetgear R6700 FirmwareNetgear R6900p FirmwareNetgear R7000 Firmware+2329/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the…
ModificadaAlta (8.8)0.88%—Netgear Cax80 FirmwareNetgear Lax20 FirmwareNetgear Mr60 FirmwareNetgear Mr80 Firmware+2929/3/202317/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service. The issue results from incorrect string matching logic…
ModificadaAlta (8.8)1.2%—Netgear D7800 FirmwareNetgear Ex6200 FirmwareNetgear Ex8000 FirmwareNetgear R6220 Firmware+529/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of…
ModificadaCrítica (9.8)0.94%—Netgear Rax40 FirmwareNetgear Rax35 FirmwareNetgear R6400v2 FirmwareNetgear R6700v3 Firmware+530/12/202217/6/2026
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152, R7000 before 1.0.11.136, R7960P before 1.4.4.94, and R8000P before…
ModificadaCrítica (9.8)1.2%—Netgear R7000 Firmware23/9/202217/6/2026
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat
ModificadaAlta (7.8)0.54%—Netgear R7000 Firmware22/9/202217/6/2026
Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.
ModificadaAlta (8.8)1.1%—Netgear R7000 Firmware13/1/202217/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper…