Netgear R7000 vulnerabilities
6 known vulnerabilities affecting netgear/r7000.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2021-34977P3HIGHCVSS 8.8v1.0.11.116_10.2.1002022-01-13
CVE-2021-34977 [HIGH] CWE-288 CVE-2021-34977: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper authentication verification before
nvd
CVE-2024-1430P4MEDIUMCVSS 6.5v1.0.11.136_10.2.1202024-02-11
CVE-2024-1430 [MEDIUM] CWE-200 CVE-2024-1430: A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. A
A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. NOTE: Th
nvd
CVE-2024-1431P4MEDIUMCVSS 6.5v1.0.11.136_10.2.1202024-02-11
CVE-2024-1431 [MEDIUM] CWE-200 CVE-2024-1431: A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affect
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253382 is the identi
nvd
CVE-2026-0417P4MEDIUMCVSS 4.5fixed in V1.0.11.2162026-06-09
CVE-2026-0417 [MEDIUM] CWE-20 CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin
Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity.
nvd
CVE-2026-9210P4MEDIUMCVSS 4.5fixed in V1.0.11.2162026-06-09
CVE-2026-9210 [MEDIUM] CWE-20 CVE-2026-9210: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
CVE-2026-0410P4MEDIUMCVSS 4.5fixed in V1.0.11.2162026-06-09
CVE-2026-0410 [MEDIUM] CWE-20 CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router
Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality.
nvd