Netgear R6220 Firmware vulnerabilities
86 known vulnerabilities affecting netgear/r6220_firmware.
Total CVEs
86
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH52MEDIUM23LOW1
Vulnerabilities
Page 4 of 5
CVE-2017-18755P3HIGHCVSS 8.8fixed in 1.1.0.502020-04-22
CVE-2017-18755 [HIGH] CWE-352 CVE-2017-18755: Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.
Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000P before 1.0.0.86, R6900P before 1.0.0.56, R7300 before 1.0.0.54, R8300 before 1.0.2.106, R8500 before 1.0.2.106, DGN2200v4 before 1.0.0.86, DGND2200Bv4 before 1.0.0.86, R6050 before 1.0.0.86, J
nvd
CVE-2016-11057P3HIGHCVSS 7.5fixed in 2017-01-062020-04-28
CVE-2016-11057 [HIGH] CWE-287 CVE-2016-11057: Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 be
Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR614 before 2017-01-06, WNR618 before 2017-01-06, JWNR2000v5 before 2017-01-06, WNR2020 before 2017-01-06, JWNR2010v5 before 2017-01-06, WNR1000v4 before 2017-01-06, WNR2020v2 before 2017-01-06, R6220 before 2017-01-06, and WNDR3700v5
nvd
CVE-2020-27873P3MEDIUMCVSS 6.5fixed in 1.1.0.1042021-02-04
CVE-2020-27873 [MEDIUM] CWE-284 CVE-2020-27873: This vulnerability allows network-adjacent attackers to disclose sensitive information on affected i
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SOAP API endpoint, which listens on TCP port 80 by default. The issue results from the lack of prop
nvd
CVE-2020-35841P3HIGHCVSS 7.6fixed in 1.1.0.1002020-12-30
CVE-2020-35841 [HIGH] CWE-79 CVE-2020-35841: Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 befor
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.76, R6700v2 before 1.2.0.62,
nvd
CVE-2020-26914P3HIGHCVSS 7.1fixed in 1.1.0.1002020-10-09
CVE-2020-26914 [HIGH] CWE-77 CVE-2020-26914: Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D62
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62,
nvd
CVE-2020-17409P4MEDIUMCVSS 6.5fixed in 1.1.0.1002020-10-13
CVE-2020-17409 [MEDIUM] CWE-288 CVE-2020-17409: This vulnerability allows network-adjacent attackers to disclose sensitive information on affected i
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6120, R6080, R6260, R6220, R6020, JNR3210, and WNR2020 routers with firmware 1.0.66. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP po
nvd
CVE-2017-18801P4MEDIUMCVSS 6.7fixed in 1.1.0.502020-04-21
CVE-2017-18801 [MEDIUM] CWE-74 CVE-2017-18801: Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.50, R6700
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.50, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.48, and D7000 before 1.0.1.50.
nvd
CVE-2017-18841P4MEDIUMCVSS 6.7fixed in 1.1.0.462020-04-20
CVE-2017-18841 [MEDIUM] CWE-74 CVE-2017-18841: Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.46, and D7000 before 1.0.1.50.
nvd
CVE-2020-13245P4MEDIUMCVSS 5.9≥ v1.0.9.6_1.2.19, ≤ v1.0.11.100_10.2.1002020-05-28
CVE-2020-13245 [MEDIUM] CWE-295 CVE-2020-13245: Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9
Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.
nvd
CVE-2017-18763P4MEDIUMCVSS 6.5fixed in 1.1.0.502020-04-22
CVE-2017-18763 [MEDIUM] CWE-20 CVE-2017-18763: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects J
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JNR1010v2 before 1.1.0.42, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.42, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6120 before 1.0.0.30, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5
nvd
CVE-2020-26916P4MEDIUMCVSS 6.3fixed in 1.1.0.1002020-10-09
CVE-2020-26916 [MEDIUM] CVE-2020-26916: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6
nvd
CVE-2017-18784P4MEDIUMCVSS 6.1fixed in 1.1.0.602020-04-22
CVE-2017-18784 [MEDIUM] CWE-79 CVE-2017-18784: Certain NETGEAR devices are affected by XSS. This affects D6200 before 1.1.00.24, D7000 before 1.0.1
Certain NETGEAR devices are affected by XSS. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R6800 before 1.2.0.12, R6900
nvd
CVE-2017-18783P4MEDIUMCVSS 6.1fixed in 1.1.0.602020-04-22
CVE-2017-18783 [MEDIUM] CWE-79 CVE-2017-18783: Certain NETGEAR devices are affected by XSS. This affects D6200 before 1.1.00.24, D7000 before 1.0.1
Certain NETGEAR devices are affected by XSS. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R680
nvd
CVE-2020-35840P4MEDIUMCVSS 5.4fixed in 1.1.0.1002020-12-30
CVE-2020-35840 [MEDIUM] CWE-79 CVE-2020-35840: Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 befor
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.76, WNR1000v4 before 1.1.0
nvd
CVE-2020-35842P4MEDIUMCVSS 5.4fixed in 1.1.0.1002020-12-30
CVE-2020-35842 [MEDIUM] CWE-79 CVE-2020-35842: Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 befor
Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JNR1010v2 before 1.1.0.62, JR6150 before 1.0.1.24, JWNR2010v5 before 1.1.0.62, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.76, WNR1000v4 before 1.1.0
nvd
CVE-2017-18778P4MEDIUMCVSS 5.5fixed in 1.1.0.602020-04-22
CVE-2017-18778 [MEDIUM] CWE-20 CVE-2017-18778: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6220 before 1.0.0.28, D6400 before 1.0.0.60, D7000 before 1.0.1.52, D7000v2 before 1.0.0.38, D7800 before 1.0.1.24, D8500 before 1.0.3.29, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.14, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 befo
nvd
CVE-2018-21231P4MEDIUMCVSS 5.4fixed in 1.1.0.502020-04-24
CVE-2018-21231 [MEDIUM] CVE-2018-21231: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.57, D6220 before 1.0.0.40, D6400 before 1.0.0.74, D7000 before 1.0.1.60, D7800 before 1.0.1.34, D8500 before 1.0.3.39, DGN2200v4 before 1.0.0.94, DGN2200Bv4 before 1.0.0.94, EX2700 before 1.0.1.42
nvd
CVE-2018-21230P4MEDIUMCVSS 5.4fixed in 1.1.0.502020-04-24
CVE-2018-21230 [MEDIUM] CVE-2018-21230: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.57, D6220 before 1.0.0.40, D6400 before 1.0.0.74, D7000 before 1.0.1.60, D7800 before 1.0.1.34, D8500 before 1.0.3.39, DGN2200v4 before 1.0.0.94, DGN2200Bv4 before 1.0.0.94, EX2700 before 1.0.1.42
nvd
CVE-2017-18702P4MEDIUMCVSS 5.4fixed in 1.1.0.602020-04-24
CVE-2017-18702 [MEDIUM] CVE-2017-18702: NETGEAR R6220 devices before 1.1.0.60 are affected by incorrect configuration of security settings.
NETGEAR R6220 devices before 1.1.0.60 are affected by incorrect configuration of security settings.
nvd
CVE-2017-18769P4MEDIUMCVSS 4.6fixed in 1.1.0.502020-04-22
CVE-2017-18769 [MEDIUM] CWE-200 CVE-2017-18769: Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.40, D6400 before 1.0.0.74, D7000 before 1.0.1.60, D7800 before 1.0.1.34, D8500 before 1.0.3.39, DGN2200v4 before 1.0.0.94, DGN2200Bv4 before 1.0.0.94, EX6200v2 before 1.0.1.50, EX7000 before 1.0.0.56, JR6150 before 1.0.1.18, R6050 be
nvd