Netgear R7800 vulnerabilities
8 known vulnerabilities affecting netgear/r7800.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-34947HIGHCVSS 8.8v1.0.2.822024-05-07
CVE-2021-34947 [HIGH] CWE-787 CVE-2021-34947: NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al
NETGEAR R7800 net-cgi Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the parsing of the soap_block_table file. The is
cvelistv5nvd
CVE-2021-27251HIGHCVSS 8.8v1.0.2.762021-04-14
CVE-2021-27251 [HIGH] CWE-319 CVE-2021-27251: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from a fallback to a insecure protocol to deliver updates. An attacker can leve
cvelistv5nvd
CVE-2021-27252HIGHCVSS 8.8vfirmware version 1.0.2.762021-04-14
CVE-2021-27252 [HIGH] CWE-78 CVE-2021-27252: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the vendor_specific DHCP opcode. The issue results from the lack of proper validation of a user
cvelistv5nvd
CVE-2021-27253HIGHCVSS 8.8vfirmware version 1.0.2.762021-04-14
CVE-2021-27253 [HIGH] CWE-122 CVE-2021-27253: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_bind.cg
cvelistv5nvd
CVE-2021-27256HIGHCVSS 8.8vfirmware version 1.0.2.762021-03-05
CVE-2021-27256 [HIGH] CWE-78 CVE-2021-27256: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided t
cvelistv5nvd
CVE-2021-27254HIGHCVSS 8.8vfirmware version 1.0.2.762021-03-05
CVE-2021-27254 [HIGH] CWE-259 CVE-2021-27254: This vulnerability allows network-adjacent attackers to bypass authentication on affected installati
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to
cvelistv5nvd
CVE-2021-27255HIGHCVSS 8.8vfirmware version 1.0.2.762021-03-05
CVE-2021-27255 [HIGH] CWE-306 CVE-2021-27255: This vulnerability allows remote attackers to execute arbitrary code on affected installations of NE
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the refresh_status.aspx endpoint. The issue results from a lack of authentication required to start a service on the ser
cvelistv5nvd
CVE-2021-27257MEDIUMCVSS 6.5vfirmware version 1.0.2.762021-03-05
CVE-2021-27257 [MEDIUM] CWE-295 CVE-2021-27257: This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded infor
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via FTP. The issue results from the lack of proper vali
cvelistv5nvd