Netgear R6700 vulnerabilities

12 known vulnerabilities affecting netgear/r6700.

Total CVEs
12
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH9MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2020-15635HIGHCVSS 8.8v1.0.4.84_10.0.582020-08-20
CVE-2020-15635 [HIGH] CWE-121 CVE-2020-15635: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific flaw exists within the acsd service, which listens on TCP port 5916 by default. The issue results
cvelistv5nvd
CVE-2020-15634MEDIUMCVSS 6.3v1.0.4.84_10.0.582020-08-20
CVE-2020-15634 [MEDIUM] CWE-134 CVE-2020-15634: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. The issue results from the lack of proper validation
cvelistv5nvd
CVE-2020-10925HIGHCVSS 8.8vV1.0.4.84_10.0.582020-07-28
CVE-2020-10925 [HIGH] CWE-295 CVE-2020-10925: This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded infor This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via HTTPS. The issue results from the lack of proper vali
cvelistv5nvd
CVE-2020-10927HIGHCVSS 8.8vV1.0.4.84_10.0.582020-07-28
CVE-2020-10927 [HIGH] CWE-327 CVE-2020-10927: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algori
cvelistv5nvd
CVE-2020-15416HIGHCVSS 8.8vV1.0.4.84_10.0.582020-07-28
CVE-2020-15416 [HIGH] CWE-121 CVE-2020-15416: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validatio
cvelistv5nvd
CVE-2020-10926HIGHCVSS 8.8vV1.0.4.84_10.0.582020-07-28
CVE-2020-10926 [HIGH] CWE-494 CVE-2020-10926: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of firmware updates. The issue results from the lack of proper validation of the firmware image p
cvelistv5nvd
CVE-2020-10929HIGHCVSS 8.8vV1.0.4.84_10.0.582020-07-28
CVE-2020-10929 [HIGH] CWE-680 CVE-2020-10929: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. The issue results from the lack of proper validation of user-suppli
cvelistv5nvd
CVE-2020-10924HIGHCVSS 8.8PoCvV1.0.4.84_10.0.582020-07-28
CVE-2020-10924 [HIGH] CWE-121 CVE-2020-10924: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by
cvelistv5nvd
CVE-2020-10928HIGHCVSS 8.4vV1.0.4.84_10.0.582020-07-28
CVE-2020-10928 [HIGH] CWE-122 CVE-2020-10928: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. The issue results from the lack of proper validation of the length
cvelistv5nvd
CVE-2020-10923HIGHCVSS 8.8PoCvV1.0.4.84_10.0.582020-07-28
CVE-2020-10923 [HIGH] CWE-305 CVE-2020-10923: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000. A crafted UPnP message can be used to bypass authentication.
cvelistv5nvd
CVE-2020-15417MEDIUMCVSS 6.3vV1.0.4.84_10.0.582020-07-28
CVE-2020-15417 [MEDIUM] CWE-121 CVE-2020-15417: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of string table file uploads. A crafted gui_region in a string table file can trigger an overfl
cvelistv5nvd
CVE-2020-10930MEDIUMCVSS 6.5vV1.0.4.84_10.0.582020-07-28
CVE-2020-10930 [MEDIUM] CWE-284 CVE-2020-10930: This vulnerability allows network-adjacent attackers to disclose sensitive information on affected i This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of URLs. The issue results from the lack of proper routing of URLs. An attacker can lev
cvelistv5nvd