NetgearCVEs & Vulnerabilities

1,316 CVEs affecting Netgear products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

1,316 CVEs→ All vendors

Most Affected Products

r7800 245r7800 firmware 245r9000 firmware 213r9000 213wndr4300 213r6700 198r7500 176r6700 firmware 174
CVE-2006-1003MEDIUM

The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges.

6 Mar 2006
5.0
CVSS
CVE-2005-4220HIGH

Netgear RP114, and possibly other versions and devices, allows remote attackers to cause a denial of service via a SYN flood attack between one system on the internal interface and another on the external interface, which temporarily stops routing between the interfaces, as demonstrated using nmap.

14 Dec 2005
7.8
CVSS
CVE-2005-0328MEDIUM

Zyxel P310, P314, P324 and Netgear RT311, RT314 running the latest firmware, allows remote attackers on the WAN to obtain the IP address of the LAN side interface by pinging a valid LAN IP address, which generates an ARP reply from the WAN address side that maps the LAN IP address to the WAN's MAC address.

2 May 2005
5.0
CVSS
CVE-2005-0290HIGH

NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.

17 Jan 2005
7.5
CVSS
CVE-2005-0291MEDIUM

Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.

17 Jan 2005
4.3
CVSS
CVE-2004-2556MEDIUM

NetGear WG602 (aka WG602v1) Wireless Access Point firmware 1.04.0 and 1.5.67 has a hardcoded account of username "super" and password "5777364", which allows remote attackers to modify the configuration.

31 Dec 2004
5.0
CVSS
CVE-2004-2557MEDIUM

NetGear WG602 (aka WG602v1) Wireless Access Point 1.7.14 has a hardcoded account of username "superman" and password "21241036", which allows remote attackers to modify the configuration.

31 Dec 2004
5.0
CVSS
CVE-2004-0611MEDIUM

Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.

6 Dec 2004
5.0
CVSS
CVE-2004-2032HIGHpoc

Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrated using a large number of %20 (hex-encoded space) sequences.

24 May 2004
7.5
CVSS
CVE-2003-1427MEDIUMpoc

Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

31 Dec 2003
6.4
CVSS
CVE-2002-1877HIGH

NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname.

31 Dec 2002
7.5
CVSS
CVE-2002-1892LOW

NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configuration file is made, which allows local users to obtain sensitive information.

31 Dec 2002
2.1
CVSS
CVE-2002-2020HIGH

Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26 uses a default administrator password and accepts admin logins on the external interface, which allows remote attackers to gain privileges if the password is not changed.

31 Dec 2002
7.5
CVSS
CVE-2002-2116MEDIUM

Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap.

31 Dec 2002
5.0
CVSS
CVE-2002-2354HIGH

Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.

31 Dec 2002
7.8
CVSS
CVE-2002-2355HIGH

Netgear FM114P firmware 1.3 wireless firewall, when configured to backup configuration information, stores DDNS (DynDNS) user name and password, MAC address filtering table and possibly other information in cleartext, which could allow local users to obtain sensitive information.

31 Dec 2002
7.1
CVSS
CVE-2002-0238HIGH

Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.

29 May 2002
7.5
CVSS
CVE-2002-0127MEDIUM

Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26, when configured to block traffic below port 1024, allows remote attackers to cause a denial of service (hang) via a port scan of the WAN port.

25 Mar 2002
5.0
CVSS
CVE-2001-0888MEDIUM

Atmel Firmware 1.3 Wireless Access Point (WAP) allows remote attackers to cause a denial of service via a SNMP request with (1) a community string other than "public" or (2) an unknown OID, which causes the WAP to deny subsequent SNMP requests.

21 Dec 2001
5.0
CVSS
CVE-2001-0514HIGH

SNMP service in Atmel 802.11b VNET-B Access Point 1.3 and earlier, as used in Netgear ME102 and Linksys WAP11, accepts arbitrary community strings with requested MIB modifications, which allows remote attackers to obtain sensitive information such as WEP keys, cause a denial of service, or gain access to the network.

21 Jul 2001
7.5
CVSS
← PrevPage 28 / 28Next →