cbcvebase.

Netgear R7800 vulnerabilities

9 known vulnerabilities affecting netgear/r7800.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-27255P3HIGHCVSS 8.8vfirmware version 1.0.2.762021-03-05
CVE-2021-27255 [HIGH] CWE-306 CVE-2021-27255: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NE This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the refresh_status.aspx endpoint. The issue results from a lack of authentication required to start a service on the ser
nvd
CVE-2021-27253P3HIGHCVSS 8.8vfirmware version 1.0.2.762021-04-14
CVE-2021-27253 [HIGH] CWE-122 CVE-2021-27253: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_bind.cg
nvd
CVE-2021-27252P3HIGHCVSS 8.8vfirmware version 1.0.2.762021-04-14
CVE-2021-27252 [HIGH] CWE-78 CVE-2021-27252: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the vendor_specific DHCP opcode. The issue results from the lack of proper validation of a user
nvd
CVE-2021-27256P3HIGHCVSS 8.8vfirmware version 1.0.2.762021-03-05
CVE-2021-27256 [HIGH] CWE-78 CVE-2021-27256: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided t
nvd
CVE-2021-34947P3HIGHCVSS 8.8v1.0.2.822024-05-07
CVE-2021-34947 [HIGH] CWE-787 CVE-2021-34947: NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of the soap_block_table file. The is
nvd
CVE-2021-27251P3HIGHCVSS 8.8v1.0.2.762021-04-14
CVE-2021-27251 [HIGH] CWE-319 CVE-2021-27251: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from a fallback to a insecure protocol to deliver updates. An attacker can leve
nvd
CVE-2021-27254P3HIGHCVSS 8.8vfirmware version 1.0.2.762021-03-05
CVE-2021-27254 [HIGH] CWE-259 CVE-2021-27254: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to
nvd
CVE-2026-9212P3HIGHCVSS 8.0fixed in V1.0.4.962026-06-09
CVE-2026-9212 [HIGH] CWE-20 CVE-2026-9212: Insufficient authentication and input validation in the listed NETGEAR models allow users connected Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.
nvd
CVE-2021-27257P3MEDIUMCVSS 6.5vfirmware version 1.0.2.762021-03-05
CVE-2021-27257 [MEDIUM] CWE-295 CVE-2021-27257: This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded infor This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via FTP. The issue results from the lack of proper vali
nvd
Netgear R7800 vulnerabilities | cvebase