Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

NETGEAR — Vulnerabilities & Security Advisories 209

Browse all 209 CVE security advisories affecting NETGEAR. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NETGEAR manufactures networking hardware, primarily consumer and small business routers, switches, and wireless access points. The company’s extensive vulnerability record, comprising 177 Common Vulnerabilities and Exposures (CVEs), highlights systemic security weaknesses in its embedded firmware. Historically, the most prevalent flaw classes include remote code execution (RCE), which allows attackers to gain full control over devices, and cross-site scripting (XSS) within web management interfaces. Privilege escalation and buffer overflow vulnerabilities are also common, often stemming from insufficient input validation and hardcoded credentials. These defects have facilitated large-scale botnet recruitment and unauthorized network access. While NETGEAR has implemented security response protocols, the high volume of disclosed issues reflects ongoing challenges in securing resource-constrained IoT devices. The persistent presence of critical flaws underscores the difficulty of maintaining robust security standards across a vast portfolio of consumer networking equipment.

CVE ID Title CVSS Severity Published
CVE-2026-9214 Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device. — R7000 CWE-20 4.3 Medium 2026-08-11
CVE-2026-11736 Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers — RAX20 CWE-20 1.9 Low 2026-08-11
CVE-2026-11735 Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models — R7000 CWE-121 1.9 Low 2026-08-11
CVE-2026-11738 Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device. — R7000 CWE-20 4.3 Medium 2026-08-11
CVE-2026-11739 Command injection vulnerability in some NETGEAR Nighthawk devices — MR60 CWE-78 4.9 Medium 2026-08-11
CVE-2026-11734 Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices. — MR70 CWE-121 1.1 Low 2026-08-11
CVE-2026-11733 Buffer overflow vulnerability in some NETGEAR Nighthawk routers — RAX41 CWE-121 1.1 Low 2026-08-11
CVE-2026-11737 Some NETGEAR Nighthawk devices allow administrators to tamper with the device — RAX20 CWE-20 4.3 Medium 2026-08-11
CVE-2026-11814 Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers — BE9300 CWE-295 4.9 Medium 2026-08-11
CVE-2026-62659 Authenticated users can make unauthorized changes on NETGEAR WAX333 Access Points — WAX333 CWE-20 - - 2026-07-14
CVE-2026-15757 Insufficient input validation vulnerability in NETGEAR DGND3700v1 modem router — DGND3700v1 CWE-20 - - 2026-07-14
CVE-2026-62656 Post-authenticated command injection vulnerability found in certain NETGEAR RAX models — RAXE450 CWE-20 - - 2026-07-14
CVE-2026-62657 Certificate validation vulnerability in NETGEAR Gaming Router and certain Nighthawk models — MR70 CWE-599 - - 2026-07-14
CVE-2026-62655 A DoS vulnerability due to stack overflow exists in certain NETGEAR Orbi models — RBR860 CWE-121 - - 2026-07-14
CVE-2026-62658 Post-authentication Command Injection Vulnerability in certain Nighthawk RAX series models — RAX43 CWE-20 - - 2026-07-14
CVE-2026-0420 Missing TLS certificate validation in NETGEAR's ReadyCloud client app — RAX120v1 CWE-325 - - 2026-06-09
CVE-2026-9212 Insufficient authentication and input validation in certain NETGEAR products — LBR1020 CWE-306 - - 2026-06-09
CVE-2026-0415 Insufficient input validation vulnerability in certain Orbi routers — RBE970 CWE-20 - - 2026-06-09
CVE-2026-0411 A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites — RBE970 CWE-200 - - 2026-06-09
CVE-2026-0414 Insufficient Input Validation Allows Unauthorized Modification of Router Software in certain NETGEAR Routers — RBE970 CWE-94 - - 2026-06-09
CVE-2026-0413 Buffer overflow vulnerability in certain NETGEAR Nighthawk routers — RBE370 CWE-121 - - 2026-06-09
CVE-2026-0417 Insufficient input validation in certain NETGEAR routers — MR60 CWE-20 - - 2026-06-09
CVE-2026-0418 Certain NETGEAR devices allow administrators to tamper with system — CBR750 CWE-15 - - 2026-06-09
CVE-2026-9210 Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router — EX3700 CWE-20 - - 2026-06-09
CVE-2026-9211 Certain NETGEAR routers allow unauthenticated users to gain control of the router — CAX30 CWE-20 - - 2026-06-09
CVE-2026-0416 Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionality — RAXE450 CWE-20 - - 2026-06-09
CVE-2026-9213 Insufficient input validation in certain NETGEAR routers — MR70 CWE-20 - - 2026-06-09
CVE-2026-3088 Unauthenticated users can disrupt router operation — RBR860 CWE-787 - - 2026-06-09
CVE-2026-0412 Insufficient input validation vulnerability in NETGEAR JR6150 Web UI — JR6150 CWE-20 - - 2026-06-09
CVE-2026-0419 Insufficient input validation vulnerability in NETGEAR JR6150 — JR6150 CWE-20 - - 2026-06-09

This page lists every published CVE security advisory associated with NETGEAR. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.