CVE-2025-12946
- EPSS 0.07%
- Veröffentlicht 09.12.2025 17:15:48
- Zuletzt bearbeitet 21.01.2026 19:29:14
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute ...
CVE-2021-34983
- EPSS 0.18%
- Veröffentlicht 07.05.2024 23:15:13
- Zuletzt bearbeitet 14.08.2025 01:40:56
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR rou...
CVE-2021-34982
- EPSS 5.57%
- Veröffentlicht 07.05.2024 23:15:13
- Zuletzt bearbeitet 14.08.2025 01:41:19
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is no...
- EPSS 0.05%
- Veröffentlicht 29.03.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:05
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mech...
CVE-2022-27645
- EPSS 0.12%
- Veröffentlicht 29.03.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:05
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. ...
CVE-2022-27642
- EPSS 0.04%
- Veröffentlicht 29.03.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:04
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ht...
- EPSS 81.82%
- Veröffentlicht 30.12.2021 22:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.
CVE-2021-20171
- EPSS 0.06%
- Veröffentlicht 30.12.2021 22:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary co...
CVE-2021-20170
- EPSS 0.16%
- Veröffentlicht 30.12.2021 22:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a passwor...
CVE-2021-20169
- EPSS 0.02%
- Veröffentlicht 30.12.2021 22:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be tran...