Vulnerabilities
Vulnerable Software
Netgear:  Security Vulnerabilities
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.
CVSS Score
9.8
EPSS Score
0.021
Published
2019-11-14
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
CVSS Score
9.8
EPSS Score
0.037
Published
2019-11-14
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
CVSS Score
6.5
EPSS Score
0.007
Published
2019-11-13
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
CVSS Score
5.4
EPSS Score
0.006
Published
2019-11-13
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
CVSS Score
9.8
EPSS Score
0.019
Published
2019-11-13
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
CVSS Score
9.8
EPSS Score
0.025
Published
2019-10-16
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
CVSS Score
6.5
EPSS Score
0.008
Published
2019-10-16
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
CVSS Score
6.1
EPSS Score
0.016
Published
2019-10-16
Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.
CVSS Score
9.8
EPSS Score
0.015
Published
2019-10-09
Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000, WNDR4500, WNDR4500v2, WNR1000, WNR1000v3, WNR3500L, and WNR3500L.
CVSS Score
8.1
EPSS Score
0.017
Published
2019-10-09


Contact Us

Shodan ® - All rights reserved