Netgear Rax43 Firmware vulnerabilities
26 known vulnerabilities affecting netgear/rax43_firmware.
Total CVEs
26
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH9MEDIUM10
Vulnerabilities
Page 2 of 2
CVE-2021-20169P4MEDIUMCVSS 6.8v1.0.3.962021-12-30
CVE-2021-20169 [MEDIUM] CWE-319 CVE-2021-20169: Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By defau
Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be transmitted in cleartext.
nvd
CVE-2026-0418P4MEDIUMCVSS 4.5fixed in 1.0.11.1122026-06-09
CVE-2026-0418 [MEDIUM] CWE-15 CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators conn
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.
nvd
CVE-2026-0417P4MEDIUMCVSS 4.5fixed in 1.0.12.1202026-06-09
CVE-2026-0417 [MEDIUM] CWE-20 CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin
Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity.
nvd
CVE-2026-9210P4MEDIUMCVSS 4.5fixed in 1.0.12.1202026-06-09
CVE-2026-9210 [MEDIUM] CWE-20 CVE-2026-9210: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
CVE-2026-0410P4MEDIUMCVSS 4.5fixed in 1.0.16.1322026-06-09
CVE-2026-0410 [MEDIUM] CWE-20 CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router
Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality.
nvd
CVE-2021-45604P4MEDIUMCVSS 4.5fixed in 1.0.3.962021-12-26
CVE-2021-45604 [MEDIUM] CWE-787 CVE-2021-45604: Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D6400 before 1.0.0.102, D8500 before 1.0.3.60, LAX20 before 1.1.6.28, MK62 before 1.0.6.116, MR60 before 1.0.6.116, MS60 before 1.0.6.116, R6300v2 before 1.0.4.50, R6400 before 1.0.1.68, R6400v2
nvd
← Previous2 / 2