Netgear

Xr300 Firmware

59 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 28.01.2026 00:00:00
  • Zuletzt bearbeitet 09.03.2026 14:41:45

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) co...

Exploit
  • EPSS 1.03%
  • Veröffentlicht 28.01.2026 00:00:00
  • Zuletzt bearbeitet 09.03.2026 14:43:22

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_a...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 15.07.2025 00:00:00
  • Zuletzt bearbeitet 11.08.2025 18:51:25

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the read_access parameter.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 15.07.2025 00:00:00
  • Zuletzt bearbeitet 12.08.2025 01:26:55

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the usb_folder parameter.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 15.07.2025 00:00:00
  • Zuletzt bearbeitet 11.08.2025 18:49:28

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.

  • EPSS 0.18%
  • Veröffentlicht 05.11.2024 15:15:27
  • Zuletzt bearbeitet 21.05.2025 20:12:14

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST ...

  • EPSS 0.18%
  • Veröffentlicht 05.11.2024 15:15:27
  • Zuletzt bearbeitet 21.05.2025 20:12:26

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST...

  • EPSS 0.19%
  • Veröffentlicht 05.11.2024 15:15:27
  • Zuletzt bearbeitet 21.05.2025 20:12:43

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST r...

  • EPSS 0.18%
  • Veröffentlicht 05.11.2024 15:15:27
  • Zuletzt bearbeitet 21.05.2025 20:12:52

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST req...

  • EPSS 0.27%
  • Veröffentlicht 05.11.2024 15:15:27
  • Zuletzt bearbeitet 21.05.2025 20:23:37

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to ex...