Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
50147029.3%CRITICAL

Related CVEs

100+
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-9213A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.MEDIUM6.931.6%Jun 9, 2026
CVE-2026-9212Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.MEDIUM5.618.5%Jun 9, 2026
CVE-2026-9211An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.MEDIUM5.214.2%Jun 9, 2026
CVE-2026-9210Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.MEDIUM4.911.9%Jun 9, 2026
CVE-2026-3088Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.MEDIUM4.927.6%Jun 9, 2026
CVE-2026-0420An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks impacting the product's confidentiality. This vulnerability affects the listed NETGEAR models.MEDIUM4.63.4%Jun 9, 2026
CVE-2026-0419Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.MEDIUM4.420.6%Jun 9, 2026
CVE-2026-0418Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.MEDIUM4.315.5%Jun 9, 2026
CVE-2026-0417Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.MEDIUM4.313.6%Jun 9, 2026
CVE-2026-0416An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.MEDIUM4.37.7%Jun 9, 2026
CVE-2026-0415Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.MEDIUM4.313.6%Jun 9, 2026
CVE-2026-0414Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.MEDIUM4.36.4%Jun 9, 2026
CVE-2026-0413A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.MEDIUM4.324.0%Jun 9, 2026
CVE-2026-0412Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and functionality. NETGEAR JR6150 reached End-of-Support status in 2018 and is no longer receiving security updates. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure continued security support and updates. This vulnerability has been identified through firmware emulation in a controlled research environment and has not been verified on production hardware.MEDIUM4.34.8%Jun 9, 2026
CVE-2026-0411An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.MEDIUM4.219.6%Jun 9, 2026
CVE-2026-0410Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.LOW1.912.3%Jun 9, 2026
CVE-2026-0409A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.MEDIUM4.816.9%Jun 9, 2026
CVE-2022-40620FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a malicious update package in order to gain arbitrary code execution on affected devices. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.HIGH7.719.1%Jan 28, 2026
CVE-2022-40619FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before 1.1.0.112, R6260 before 1.1.0.88, R7000 before 1.0.11.134, R8900 before 1.0.5.42, R9000 before 1.0.5.42, and XR300 before 1.0.3.72 and Orbi RBR20 before 2.7.2.26, RBR50 before 2.7.4.26, RBS20 before 2.7.2.26, and RBS50 before 2.7.4.26.HIGH7.780.6%Jan 28, 2026
CVE-2026-0408A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and password submitted to the router GUI.MEDIUM6.113.5%Jan 13, 2026