CVE-2021-34983
- EPSS 0.18%
- Published 07.05.2024 23:15:13
- Last modified 14.08.2025 01:40:56
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR rou...
CVE-2021-34982
- EPSS 5.57%
- Published 07.05.2024 23:15:13
- Last modified 14.08.2025 01:41:19
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is no...
- EPSS 0.06%
- Published 29.03.2023 19:15:08
- Last modified 21.11.2024 06:56:05
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mech...
CVE-2022-27645
- EPSS 0.17%
- Published 29.03.2023 19:15:08
- Last modified 21.11.2024 06:56:05
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. ...
CVE-2022-27642
- EPSS 0.04%
- Published 29.03.2023 19:15:08
- Last modified 21.11.2024 06:56:04
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ht...
CVE-2021-20166
- EPSS 64.23%
- Published 30.12.2021 22:15:09
- Last modified 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the applicaiton.
CVE-2021-20171
- EPSS 0.06%
- Published 30.12.2021 22:15:09
- Last modified 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the primary co...
CVE-2021-20170
- EPSS 0.16%
- Published 30.12.2021 22:15:09
- Last modified 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a passwor...
CVE-2021-20169
- EPSS 0.02%
- Published 30.12.2021 22:15:09
- Last modified 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be tran...
CVE-2021-20168
- EPSS 0.05%
- Published 30.12.2021 22:15:09
- Last modified 21.11.2024 05:46:03
Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is able to connect to the UART port via a serial connection, login with default credentials, and execute c...