CVE-2026-0420
- EPSS 0.14%
- Veröffentlicht 09.06.2026 15:50:53
- Zuletzt bearbeitet 23.07.2026 08:10:00
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnera...
CVE-2023-27358
- EPSS 0.88%
- Veröffentlicht 03.05.2024 02:15:13
- Zuletzt bearbeitet 09.01.2025 15:37:04
NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit...
CVE-2022-27642
- EPSS 0.88%
- Veröffentlicht 29.03.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:04
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ht...
CVE-2022-27645
- EPSS 1.29%
- Veröffentlicht 29.03.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:05
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. ...
- EPSS 1.47%
- Veröffentlicht 29.03.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:05
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mech...
CVE-2022-48196
- EPSS 0.94%
- Veröffentlicht 30.12.2022 08:15:07
- Zuletzt bearbeitet 10.04.2025 19:15:50
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX35 before 1.0.2.60, R6400v2 before 1.0.4.122, R6700v3 before 1.0.4.122, R6900P before 1.3.3.152, R7000P before 1.3.3.152,...
CVE-2021-45604
- EPSS 0.37%
- Veröffentlicht 26.12.2021 01:15:17
- Zuletzt bearbeitet 21.11.2024 06:32:38
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D6400 before 1.0.0.102, D8500 before 1.0.3.60, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, M...
CVE-2021-45549
- EPSS 0.63%
- Veröffentlicht 26.12.2021 01:15:15
- Zuletzt bearbeitet 21.11.2024 06:32:29
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 before 1.1.6.122, MR60 before 1.1.6.122, MS60 before 1.1.6.122, R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, R6900P be...
CVE-2021-45493
- EPSS 0.77%
- Veröffentlicht 26.12.2021 01:15:12
- Zuletzt bearbeitet 21.11.2024 06:32:20
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.
CVE-2021-41449
- EPSS 1.55%
- Veröffentlicht 09.12.2021 14:15:12
- Zuletzt bearbeitet 09.07.2026 01:17:03
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via s...