CVE-2019-20712
- EPSS 0.24%
- Published 16.04.2020 19:15:24
- Last modified 21.11.2024 04:39:08
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, R...
CVE-2019-20700
- EPSS 0.39%
- Published 16.04.2020 19:15:23
- Last modified 21.11.2024 04:39:07
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.44, D6400 before 1.0.0.78, D7000v2 before 1.0.0.51, D8500 before 1.0.3.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 b...
CVE-2019-20692
- EPSS 0.23%
- Published 16.04.2020 19:15:23
- Last modified 21.11.2024 04:39:05
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.44, D6400 before 1.0.0.78, D7000v2 before 1.0.0.51, D8500 before 1.0.3.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 b...
CVE-2019-17373
- EPSS 0.93%
- Published 09.10.2019 13:15:20
- Last modified 21.11.2024 04:32:12
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, ...
CVE-2016-5649
- EPSS 75.11%
- Published 24.07.2018 15:29:00
- Last modified 21.11.2024 02:54:45
A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When proces...
CVE-2017-6366
- EPSS 0.25%
- Published 15.03.2017 14:59:00
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dn...
- EPSS 87.65%
- Published 22.02.2017 23:59:00
- Last modified 20.04.2025 01:37:25
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.