CVE-2022-40620
- EPSS 0.13%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 09.03.2026 14:41:45
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) co...
CVE-2022-40619
- EPSS 1.03%
- Veröffentlicht 28.01.2026 00:00:00
- Zuletzt bearbeitet 09.03.2026 14:43:22
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_a...
CVE-2021-34947
- EPSS 0.39%
- Veröffentlicht 07.05.2024 23:15:07
- Zuletzt bearbeitet 14.08.2025 01:42:44
NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploi...
CVE-2021-45658
- EPSS 0.24%
- Veröffentlicht 26.12.2021 01:15:20
- Zuletzt bearbeitet 21.11.2024 06:32:48
Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1.78, EX6250 before 1.0.0.110, E...
CVE-2021-45642
- EPSS 0.52%
- Veröffentlicht 26.12.2021 01:15:19
- Zuletzt bearbeitet 21.11.2024 06:32:45
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.64, EX6250 before 1.0.0.134, EX7700 before 1.0.0.222, LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, R8900 before 1.0.5.26, R9000 be...
- EPSS 1.02%
- Veröffentlicht 26.12.2021 01:15:18
- Zuletzt bearbeitet 21.11.2024 06:32:41
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.134, EX7700 before 1.0.0.216, EX8000 before 1.0.1.232, LBR1020 before 2.6.3.58, LBR20 before 2.6.3.50...
- EPSS 1.53%
- Veröffentlicht 26.12.2021 01:15:18
- Zuletzt bearbeitet 21.11.2024 06:32:41
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.64, EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.134, EX7700 before 1.0.0.216, EX8000 before 1.0.1.232, LBR20 before 2.6.3.50, ...
CVE-2021-45548
- EPSS 0.82%
- Veröffentlicht 26.12.2021 01:15:15
- Zuletzt bearbeitet 21.11.2024 06:32:29
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.60, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.128, EX6400...
CVE-2021-45552
- EPSS 0.19%
- Veröffentlicht 26.12.2021 01:15:15
- Zuletzt bearbeitet 21.11.2024 06:32:29
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.108, and XR700 bef...
CVE-2021-38538
- EPSS 0.25%
- Veröffentlicht 11.08.2021 00:17:53
- Zuletzt bearbeitet 21.11.2024 06:17:22
Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, ...