Show filters
1,188 Total Results
Displaying 151-160 of 1,188
Sort by:
Attacker Value
Unknown

CVE-2022-38956

Disclosure Date: September 20, 2022 (last updated February 24, 2025)
An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to replace the user-uploaded firmware image with an original old firmware image. This affects Firmware 1.1.1_1.1.9 and earlier.
Attacker Value
Unknown

CVE-2022-38955

Disclosure Date: September 20, 2022 (last updated February 24, 2025)
An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the CRC check. A successful attack can either introduce a backdoor to the device or make the device DoS. This affects Firmware Version: 1.1.1_1.1.9.
Attacker Value
Unknown

CVE-2022-30079

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.
Attacker Value
Unknown

CVE-2021-34236

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'.
Attacker Value
Unknown

CVE-2022-30078

Disclosure Date: September 07, 2022 (last updated February 24, 2025)
NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameters.
Attacker Value
Unknown

CVE-2022-31876

Disclosure Date: June 17, 2022 (last updated February 23, 2025)
netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.
Attacker Value
Unknown

CVE-2022-29383

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.
Attacker Value
Unknown

CVE-2022-27947

Disclosure Date: March 26, 2022 (last updated February 23, 2025)
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, or ipv6_lan_length parameter.
Attacker Value
Unknown

CVE-2022-27946

Disclosure Date: March 26, 2022 (last updated February 23, 2025)
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to admin_account.cgi.
Attacker Value
Unknown

CVE-2022-27945

Disclosure Date: March 26, 2022 (last updated February 23, 2025)
NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via shell metacharacters in the sysNewPasswd and sysConfirmPasswd parameters to password.cgi.