Netgear Cbr40 Firmware vulnerabilities

48 known vulnerabilities affecting netgear/cbr40_firmware.

Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH21MEDIUM8

Vulnerabilities

Page 1 of 3
CVE-2024-28340HIGHCVSS 7.5v2.5.0.282024-03-12
CVE-2024-28340 [HIGH] CWE-200 CVE-2024-28340: An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5 An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
nvd
CVE-2024-28339MEDIUMCVSS 5.4v2.5.0.282024-03-12
CVE-2024-28339 [MEDIUM] CWE-200 CVE-2024-28339: An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28 An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.
nvd
CVE-2023-36187CRITICALCVSS 9.8fixed in 2.5.0.242023-09-01
CVE-2023-36187 [CRITICAL] CWE-120 CVE-2023-36187: Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthentic Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.
nvd
CVE-2022-27644HIGHCVSS 8.8fixed in 2.5.0.282023-03-29
CVE-2022-27644 [HIGH] CWE-295 CVE-2022-27644: This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded infor This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper va
nvd
CVE-2022-27646HIGHCVSS 8.8fixed in 2.5.0.282023-03-29
CVE-2022-27646 [HIGH] CWE-121 CVE-2022-27646: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled daemon. A crafted circleinfo.txt fil
nvd
CVE-2021-45508CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45508 [CRITICAL] CVE-2021-45508: Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, C Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, and RBR850 before 3.2.17.12.
nvd
CVE-2021-45630CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45630 [CRITICAL] CWE-77 CVE-2021-45630: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
nvd
CVE-2021-45620CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45620 [CRITICAL] CWE-77 CVE-2021-45620: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, LAX20 before 1.1.6.28, MR60 before 1.0.6.116, MR80 before 1.1.2.20, MS60 before 1.0.6.116, MS80 before 1.1.2.20, MK62 before 1.0.6.116, MK83 before 1.1.2.2
nvd
CVE-2021-45622CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45622 [CRITICAL] CWE-77 CVE-2021-45622: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116, R6400 before 1.0.1.70, R6400v2 before 1
nvd
CVE-2021-45507CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45507 [CRITICAL] CVE-2021-45507: Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, C Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBW30 before 2.6.2.2, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, and RBS40V before 2.6.2.8.
nvd
CVE-2021-45613CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45613 [CRITICAL] CWE-77 CVE-2021-45613: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116, MR80 before 1.1.2.20, MS80 before 1.1.2.20, RAX15 before 1.0.3.96, RAX20 before 1.0.
nvd
CVE-2021-45504CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45504 [CRITICAL] CVE-2021-45504: Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, C Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
nvd
CVE-2021-45621CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45621 [CRITICAL] CWE-77 CVE-2021-45621: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX3700 before 1.0.0.94, EX3800 before 1.0.0.94, EX6120 before 1.0.0.64, EX6130 before 1.0.0.44, EX7000 before 1.0.1.104, EX7500 before 1.0.0.74, LAX20 bef
nvd
CVE-2021-45612CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45612 [CRITICAL] CWE-77 CVE-2021-45612: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 before 1.0.0.58, EAX80 before 1.0.1.68, EX7500 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116, R6400v2 before 1.0.4.118, R6700v3 befor
nvd
CVE-2021-45617CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45617 [CRITICAL] CWE-77 CVE-2021-45617: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX7500 before 1.0.0.72, R6400 before 1.0.1.68, R6900P before 1.3.2.132, R7000 before 1.0.11.116, R7000P before 1.3.2.132, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 bef
nvd
CVE-2021-45509CRITICALCVSS 9.8fixed in 2.5.0.242021-12-26
CVE-2021-45509 [CRITICAL] CVE-2021-45509: Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, R Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
nvd
CVE-2021-45599HIGHCVSS 8.8fixed in 2.5.0.242021-12-26
CVE-2021-45599 [HIGH] CWE-77 CVE-2021-45599: Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
nvd
CVE-2021-45615HIGHCVSS 8.8fixed in 2.5.0.242021-12-26
CVE-2021-45615 [CRITICAL] CWE-77 CVE-2021-45615: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, R8300 before 1.0.2.154, R8500 before 1.0.2.154, RBK752 before 3.2.17.12, RBR750 before 3.2.17.12, RBS750 before 3.2.17.12, RBK852
nvd
CVE-2021-45529HIGHCVSS 7.2fixed in 2.3.5.122021-12-26
CVE-2021-45529 [HIGH] CWE-120 CVE-2021-45529: Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects CBR Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects CBR40 before 2.3.5.12, D7000v2 before 1.0.0.66, D8500 before 1.0.3.58, R6400 before 1.0.1.70, R7000 before 1.0.11.126, R6900P before 1.3.2.124, R7000P before 1.3.2.124, R7900 before 1.0.4.30, R8000 before 1.0.4.52, and WNR3500Lv2 before 1.2.0.62.
nvd
CVE-2021-45601HIGHCVSS 8.8fixed in 2.5.0.242021-12-26
CVE-2021-45601 [HIGH] CWE-77 CVE-2021-45601: Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
nvd