Netgear R6700 Firmware vulnerabilities
172 known vulnerabilities affecting netgear/r6700_firmware.
Total CVEs
172
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL11HIGH104MEDIUM56LOW1
Vulnerabilities
Page 1 of 9
CVE-2016-6277P1HIGHCVSS 8.8KEVPoC≤ 1.0.1.142016-12-14
CVE-2016-6277 [HIGH] CWE-352 CVE-2016-6277: NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell met
nvd
CVE-2020-27866P1HIGHCVSS 8.8ExploitedPoCfixed in 1.2.0.762021-02-12
CVE-2020-27866 [HIGH] CWE-288 CVE-2020-27866: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_ht
nvd
CVE-2020-27867P1MEDIUMCVSS 6.8Exploitedfixed in 1.2.0.762021-02-12
CVE-2020-27867 [MEDIUM] CWE-77 CVE-2020-27867: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanis
nvd
CVE-2020-10924P2HIGHCVSS 8.8PoCv1.0.4.84_10.0.582020-07-28
CVE-2020-10924 [HIGH] CWE-121 CVE-2020-10924: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by
nvd
CVE-2020-10923P2HIGHCVSS 8.8PoCv1.0.4.84_10.0.582020-07-28
CVE-2020-10923 [HIGH] CWE-305 CVE-2020-10923: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000. A crafted UPnP message can be used to bypass authentication.
nvd
CVE-2022-27643P2HIGHCVSS 8.8fixed in 1.0.4.1262023-03-29
CVE-2022-27643 [HIGH] CWE-120 CVE-2022-27643: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process does not properly validate th
nvd
CVE-2020-15636P2CRITICALCVSS 9.8fixed in 1.0.4.982020-08-20
CVE-2020-15636 [CRITICAL] CWE-121 CVE-2020-15636: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900, R8000, RS400, and XR300 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific flaw exists within the check_ra service. A crafted raePolicyVersion i
nvd
CVE-2020-11789P2CRITICALCVSS 9.8fixed in 1.0.2.8fixed in 1.0.4.842020-04-15
CVE-2020-11789 [CRITICAL] CWE-77 CVE-2020-11789: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
nvd
CVE-2018-21162P2CRITICALCVSS 9.8fixed in 1.0.1.162020-04-23
CVE-2018-21162 [CRITICAL] CWE-78 CVE-2018-21162: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6250 before 1.0.4.8, R6300v2 before 1.0.4.6, R6400 before 1.0.1.12, R6700 before 1.0.1.16, R7000 before 1.0.7.10, R7100LG before 1.0.0.42, R7300DST before 1.0.0.44, R7900 befo
nvd
CVE-2023-33533P2HIGHCVSS 8.8v1.0.2.262023-06-06
CVE-2023-33533 [HIGH] CWE-77 CVE-2023-33533: Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmw
Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.
nvd
CVE-2020-15416P2HIGHCVSS 8.8v1.0.4.84_10.0.582020-07-28
CVE-2020-15416 [HIGH] CWE-121 CVE-2020-15416: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper validatio
nvd
CVE-2020-26927P2CRITICALCVSS 9.8fixed in 1.2.0.622020-10-09
CVE-2020-26927 [CRITICAL] CVE-2020-26927: Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40,
Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.66, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62,
nvd
CVE-2021-20173P2HIGHCVSS 8.8v1.0.4.1202021-12-30
CVE-2021-20173 [HIGH] CWE-78 CVE-2021-20173: Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update funct
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values.
nvd
CVE-2020-15635P2HIGHCVSS 8.8fixed in 1.0.4.982020-08-20
CVE-2020-15635 [HIGH] CWE-121 CVE-2020-15635: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific flaw exists within the acsd service, which listens on TCP port 5916 by default. The issue results
nvd
CVE-2022-27646P2HIGHCVSS 8.8fixed in 1.0.4.1262023-03-29
CVE-2022-27646 [HIGH] CWE-121 CVE-2022-27646: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the circled daemon. A crafted circleinfo.txt fil
nvd
CVE-2021-40847P3HIGHCVSS 8.1v1.0.2.162021-09-21
CVE-2021-40847 [HIGH] CWE-319 CVE-2021-40847: The update process of the Circle Parental Control Service on various NETGEAR routers allows remote a
The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR t
nvd
CVE-2017-18735P3HIGHCVSS 8.8fixed in 1.2.0.42020-04-23
CVE-2017-18735 [HIGH] CWE-74 CVE-2017-18735: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, and R6900v2 before 1.2.0.4.
nvd
CVE-2017-18736P3HIGHCVSS 8.8fixed in 1.2.0.42020-04-23
CVE-2017-18736 [HIGH] CWE-74 CVE-2017-18736: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, and WNDR3700v5 before 1.1.0.48.
nvd
CVE-2022-27645P3HIGHCVSS 8.8fixed in 1.0.4.1262023-03-29
CVE-2022-27645 [HIGH] CWE-306 CVE-2022-27645: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacke
nvd
CVE-2017-18734P3HIGHCVSS 8.8fixed in 1.2.0.42020-04-23
CVE-2017-18734 [HIGH] CWE-74 CVE-2017-18734: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1
nvd
1 / 9Next →