Netgear Wndr4700 Firmware vulnerabilities

6 known vulnerabilities affecting netgear/wndr4700_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2LOW1

Vulnerabilities

Page 1 of 1
CVE-2013-3071CRITICALCVSS 9.8v1.0.0.342020-01-28
CVE-2013-3071 [CRITICAL] CWE-287 CVE-2013-3071: NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass. NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
nvd
CVE-2013-3074HIGHCVSS 7.5v1.0.0.342020-01-28
CVE-2013-3074 [HIGH] CWE-400 CVE-2013-3074: NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denia NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
nvd
CVE-2013-3073CRITICALCVSS 9.8v1.0.0.342019-11-14
CVE-2013-3073 [CRITICAL] CWE-22 CVE-2013-3073: A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34. A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
nvd
CVE-2013-3072CRITICALCVSS 9.8v1.0.0.342019-11-14
CVE-2013-3072 [CRITICAL] CWE-287 CVE-2013-3072: An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http: An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http:///apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.
nvd
CVE-2013-3070HIGHCVSS 7.5v1.0.0.342019-11-14
CVE-2013-3070 [HIGH] CWE-200 CVE-2013-3070: An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
nvd
CVE-2013-3069LOWCVSS 3.5v1.0.0.342014-04-25
CVE-2013-3069 [LOW] CWE-79 CVE-2013-3069: Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1) UserName or (2) Password to the NAS User Setup page, (3) deviceName to USB_advanced.htm, or (4) Network Key to the Wireless Setup page.
nvd