Netgear Wnr1000 Firmware vulnerabilities
35 known vulnerabilities affecting netgear/wnr1000_firmware.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH19MEDIUM12
Vulnerabilities
Page 1 of 2
CVE-2019-20488P2CRITICALCVSS 9.8v1.1.0.542020-03-02
CVE-2019-20488 [CRITICAL] CWE-78 CVE-2019-20488: An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web manag
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter.
nvd
CVE-2013-3316P2CRITICALCVSS 9.8fixed in 1.0.2.602020-01-29
CVE-2013-3316 [CRITICAL] CWE-287 CVE-2013-3316: Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
nvd
CVE-2019-20489P2CRITICALCVSS 9.8v1.1.0.542020-03-02
CVE-2019-20489 [CRITICAL] CWE-287 CVE-2019-20489: An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.c
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a cookie, reads the Set-Cookie header
nvd
CVE-2013-3317P2CRITICALCVSS 9.8fixed in 1.0.2.602020-01-29
CVE-2013-3317 [CRITICAL] CWE-287 CVE-2013-3317: Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak ke
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
nvd
CVE-2017-18734P3HIGHCVSS 8.8fixed in 1.1.0.442020-04-23
CVE-2017-18734 [HIGH] CWE-74 CVE-2017-18734: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1
nvd
CVE-2017-18737P3HIGHCVSS 8.8fixed in 1.1.0.442020-04-23
CVE-2017-18737 [HIGH] CWE-74 CVE-2017-18737: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1
nvd
CVE-2017-18764P3HIGHCVSS 8.8fixed in 1.1.0.442020-04-22
CVE-2017-18764 [HIGH] CWE-74 CVE-2017-18764: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6100 before 1.0.1.14, R6120 before 1.0.0.30, R6220 befo
nvd
CVE-2018-21226P3HIGHCVSS 8.8fixed in 1.1.0.482020-04-28
CVE-2018-21226 [HIGH] CWE-269 CVE-2018-21226: Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.4
Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1.1.0.48, WNR2020 before 1.1.0.48, and WNR2050 before 1.1.0.48.
nvd
CVE-2017-18787P3HIGHCVSS 7.8fixed in 1.1.0.442020-04-22
CVE-2017-18787 [HIGH] CWE-74 CVE-2017-18787: Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050, before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
nvd
CVE-2017-18786P3HIGHCVSS 7.8fixed in 1.1.0.442020-04-22
CVE-2017-18786 [HIGH] CWE-74 CVE-2017-18786: Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.
nvd
CVE-2017-18776P3HIGHCVSS 8.4fixed in 1.1.0.402020-04-22
CVE-2017-18776 [HIGH] CWE-287 CVE-2017-18776: Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55,
Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108, R7500v2 before 1.0.3.10, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48,
nvd
CVE-2018-21169P3HIGHCVSS 8.8fixed in 1.1.0.462020-04-27
CVE-2018-21169 [HIGH] CVE-2018-21169: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7000 before 2018-03-01, D7800 before 1.0.1.31, D8500 before 1.0.3.36, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.14, JWNR2010v5 before 1.1.0.46, PR2000 before 2018-03-01, R6050 before 1.0.1.14, R6220 before 1.1.0.60, R6400 before 1.1.0.26, R6400v2 before 1.
nvd
CVE-2017-18703P3HIGHCVSS 8.8fixed in 1.1.0.462020-04-24
CVE-2017-18703 [HIGH] CWE-352 CVE-2017-18703: Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.
Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, EX6100v2 before 1.0.1.60, EX6150v2 before 1.0.1.60, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.16, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.18, R6020 before 1.0.0.26, R6
nvd
CVE-2019-20487P3HIGHCVSS 8.8v1.1.0.542020-03-02
CVE-2019-20487 [HIGH] CWE-352 CVE-2019-20487: An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI.
nvd
CVE-2018-21139P3HIGHCVSS 7.5fixed in 1.1.0.542020-04-23
CVE-2018-21139 [HIGH] CWE-200 CVE-2018-21139: Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 befo
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.58, D6200 before 1.1.00.30, D6220 before 1.0.0.46, D6400 before 1.0.0.82, D7000 before 1.0.1.68, D7000v2 before 1.0.0.51, D7800 before 1.0.1.42, D8500 before 1.0.3.42, DC112A before 1.0.0.40, DGN2200
nvd
CVE-2017-18782P3HIGHCVSS 8.8fixed in 1.1.0.442020-04-22
CVE-2017-18782 [HIGH] CWE-352 CVE-2017-18782: Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.
Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R680
nvd
CVE-2017-18749P3HIGHCVSS 8.8fixed in 1.1.0.442020-04-23
CVE-2017-18749 [HIGH] CWE-352 CVE-2017-18749: Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before
Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 before 1.0.1.10, R6100 before 1.0.1.16, R6220 before 1.1.0.50, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.40, WNDR3700v4 before 1.0.2.88, WNDR3700v5 before 1.1.0.
nvd
CVE-2017-18779P3HIGHCVSS 7.8fixed in 1.1.0.442020-04-22
CVE-2017-18779 [HIGH] CWE-120 CVE-2017-18779: Certain NETGEAR devices are affected by a buffer overflow. This affects D6200 before 1.1.00.24, D700
Certain NETGEAR devices are affected by a buffer overflow. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1
nvd
CVE-2017-18781P3HIGHCVSS 8.8fixed in 1.1.0.442020-04-22
CVE-2017-18781 [HIGH] CWE-352 CVE-2017-18781: Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.
Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, JR6150 before 1.0.1.12, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26, R6120 before 1.0.0.36, R6220 before 1.1.0.60, R6700v2 before 1.2.0.12, R680
nvd
CVE-2017-18791P3HIGHCVSS 8.8fixed in 1.1.0.402020-04-21
CVE-2017-18791 [HIGH] CWE-352 CVE-2017-18791: Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 befor
Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050 before 1.1.0.40, WNR614 before 1.1.0.40, WNR618 before 1.1.0.40, and D7000
nvd
1 / 2Next →