cbcvebase.

Netgear Wnr2000 Firmware vulnerabilities

93 known vulnerabilities affecting netgear/wnr2000_firmware.

Total CVEs
93
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH27MEDIUM62LOW1

Vulnerabilities

Page 1 of 5
CVE-2017-6862P1CRITICALCVSS 9.8KEVfixed in 1.0.0.42fixed in 1.0.0.66+1 more2017-05-26
CVE-2017-6862 [CRITICAL] CWE-120 CVE-2017-6862: NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.
nvd
CVE-2023-50089P2CRITICALCVSS 9.8v1.0.0.702023-12-15
CVE-2023-50089 [CRITICAL] CWE-77 CVE-2023-50089: A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
nvd
CVE-2018-21153P3CRITICALCVSS 9.8fixed in 1.0.0.642020-04-27
CVE-2018-21153 [CRITICAL] CWE-120 CVE-2018-21153: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, EX2700 before 1.0.1.32, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.70, EX6200v2 before 1.0.1.62, EX6400 before 1.0.1.78, EX7300 before 1.0.1.62, EX8000 before 1.0.0.114, R6100 before 1.0.1.22, R7
nvd
CVE-2017-18762P3HIGHCVSS 8.8fixed in 1.0.0.582020-04-22
CVE-2017-18762 [HIGH] CWE-74 CVE-2017-18762: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6100 before 1.0.0.57, R6100 before 1.0.1.16, R6900P before 1.2.0.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R7100LG before 1.0.0.40, WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.90, WNDR430
nvd
CVE-2017-18764P3HIGHCVSS 8.8fixed in 1.0.0.582020-04-22
CVE-2017-18764 [HIGH] CWE-74 CVE-2017-18764: Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6100 before 1.0.1.14, R6120 before 1.0.0.30, R6220 befo
nvd
CVE-2018-21218P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21218 [HIGH] CWE-120 CVE-2018-21218: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v
nvd
CVE-2018-21224P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21224 [HIGH] CWE-120 CVE-2018-21224: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR
nvd
CVE-2018-21219P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21219 [HIGH] CWE-120 CVE-2018-21219: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v
nvd
CVE-2018-21220P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21220 [HIGH] CWE-120 CVE-2018-21220: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v
nvd
CVE-2018-21223P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21223 [HIGH] CWE-120 CVE-2018-21223: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR
nvd
CVE-2018-21222P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21222 [HIGH] CWE-120 CVE-2018-21222: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR
nvd
CVE-2017-18772P3HIGHCVSS 8.8fixed in 1.2.0.82020-04-22
CVE-2017-18772 [HIGH] CWE-287 CVE-2017-18772: Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST before 1.0.0.52, R7900 before 1.0.1.12, R8000 before 1.0.3.24, R8500 before 1.0.
nvd
CVE-2017-18738P3HIGHCVSS 8.8fixed in 1.0.0.582020-04-23
CVE-2017-18738 [HIGH] CWE-787 CVE-2017-18738: Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX6150v2 before 1.0.1.54, R6400 before 1.0.1.24, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R6900P before 1.2.0.22, R7100LG before 1.0.0.32, R7300DST before 1.0.0.
nvd
CVE-2018-21211P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-28
CVE-2018-21211 [HIGH] CWE-120 CVE-2018-21211: Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affec Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D7800 before 1.0.1.30, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v
nvd
CVE-2018-21176P3HIGHCVSS 7.2fixed in 1.0.0.622020-04-27
CVE-2018-21176 [HIGH] CWE-787 CVE-2018-21176: Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, R7500 before 1.0.0.122, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 befo
nvd
CVE-2017-18705P3HIGHCVSS 8.8fixed in 1.0.0.622020-04-24
CVE-2017-18705 [HIGH] CVE-2017-18705: Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.88, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000
nvd
CVE-2019-5054P3HIGHCVSS 7.5v1.0.0.702019-09-11
CVE-2019-5054 [HIGH] CWE-476 CVE-2019-5054: An exploitable denial-of-service vulnerability exists in the session handling functionality of the N An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated a
nvd
CVE-2018-21175P3HIGHCVSS 7.2fixed in 1.0.0.622020-04-27
CVE-2018-21175 [HIGH] CWE-787 CVE-2018-21175: Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.
nvd
CVE-2017-18776P3HIGHCVSS 8.4fixed in 1.0.0.422020-04-22
CVE-2017-18776 [HIGH] CWE-287 CVE-2017-18776: Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108, R7500v2 before 1.0.3.10, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48,
nvd
CVE-2019-5055P3HIGHCVSS 7.5v1.0.0.702019-09-11
CVE-2019-5055 [HIGH] CWE-476 CVE-2019-5055: An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on t An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in an invalid sequence to the service can cause a null pointer dereference, resulting in the hostapd service crashing. An unauthenticated attacker can send a
nvd
Netgear Wnr2000 Firmware vulnerabilities | cvebase