Netgear Raxe500 Firmware vulnerabilities
10 known vulnerabilities affecting netgear/raxe500_firmware.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2021-34991P2HIGHCVSS 8.8fixed in 1.0.8.702021-11-15
CVE-2021-34991 [HIGH] CWE-121 CVE-2021-34991: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installat
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on TCP port 5000 by default. When parsing the uuid request header, the proce
nvd
CVE-2021-34982P2HIGHCVSS 8.8fixed in 1.0.8.702024-05-07
CVE-2021-34982 [HIGH] CWE-121 CVE-2021-34982: NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the httpd service, which lis
nvd
CVE-2026-9213P3HIGHCVSS 8.1fixed in 1.2.14.1142026-06-09
CVE-2026-9213 [HIGH] CWE-20 CVE-2026-9213: A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercep
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
nvd
CVE-2025-12946P3HIGHCVSS 7.5fixed in 1.2.14.1142025-12-09
CVE-2025-12946 [HIGH] CWE-20 CVE-2025-12946: A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper i
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run.
This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6
nvd
CVE-2021-34983P3MEDIUMCVSS 6.5fixed in 1.0.8.702024-05-07
CVE-2021-34983 [MEDIUM] CWE-306 CVE-2021-34983: NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure V
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within
nvd
CVE-2026-0418P4MEDIUMCVSS 4.5fixed in 1.0.10.862026-06-09
CVE-2026-0418 [MEDIUM] CWE-15 CVE-2026-0418: Insufficient configuration management in the listed devices allows authenticated administrators conn
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network
to tamper with the system.
nvd
CVE-2026-0417P4MEDIUMCVSS 4.5fixed in 1.0.10.862026-06-09
CVE-2026-0417 [MEDIUM] CWE-20 CVE-2026-0417: Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated admin
Insufficient input validation vulnerability in the listed NETGEAR devices allows
authenticated administrators connected to the local network to tamper with
the router's integrity.
nvd
CVE-2026-9210P4MEDIUMCVSS 4.5fixed in 1.0.10.862026-06-09
CVE-2026-9210 [MEDIUM] CWE-20 CVE-2026-9210: Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated admini
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
nvd
CVE-2026-0410P4MEDIUMCVSS 4.5fixed in 1.2.14.1142026-06-09
CVE-2026-0410 [MEDIUM] CWE-20 CVE-2026-0410: Authenticated administrators connected to the local network can gain elevated access to the router
Authenticated administrators connected to the local network can gain
elevated access to the router and make unauthorized changes to router
software and functionality.
nvd
CVE-2026-0416P4MEDIUMCVSS 4.5fixed in 1.2.14.1142026-06-09
CVE-2026-0416 [MEDIUM] CWE-20 CVE-2026-0416: An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.
nvd