Product:

R7100lg_firmware

(Netgear)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 75
Date Id Summary Products Score Patch Annotated
2021-12-26 CVE-2021-45640 Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1.1.00.34, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.74, D7000v2 before 1.0.0.53, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, DM200 before 1.0.0.61, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6120 before 1.0.0.46, EX6130... D3600_firmware, D6000_firmware, D6200_firmware, D6220_firmware, D6400_firmware, D7000_firmware, D7000v2_firmware, D7800_firmware, D8500_firmware, Dc112a_firmware, Dgn2200bv4_firmware, Dgn2200v4_firmware, Dm200_firmware, Ex3700_firmware, Ex3800_firmware, Ex6120_firmware, Ex6130_firmware, Ex7000_firmware, Pr2000_firmware, R6220_firmware, R6230_firmware, R6250_firmware, R6300v2_firmware, R6400_firmware, R6400v2_firmware, R6700_firmware, R6700v3_firmware, R6900_firmware, R7000_firmware, R7100lg_firmware, R7500v2_firmware, R7900p_firmware, R8000p_firmware, R8900_firmware, R9000_firmware, Rbk20_firmware, Rbk40_firmware, Rbk50_firmware, Rbr20_firmware, Rbr40_firmware, Rbr50_firmware, Rbs20_firmware, Rbs40_firmware, Rbs50_firmware, Wn3000rpv2_firmware, Wndr3400v3_firmware, Wnr2000v5_firmware, Wnr2020_firmware, Wnr3500lv2_firmware, Xr450_firmware, Xr500_firmware 7.2
2021-12-26 CVE-2021-45641 Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1.1.00.34, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.74, D7000v2 before 1.0.0.53, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200Bv4 before 1.0.0.109, DGN2200v4 before 1.0.0.110, DM200 before 1.0.0.61, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6120 before 1.0.0.46, EX6130... D3600_firmware, D6000_firmware, D6200_firmware, D6220_firmware, D6400_firmware, D7000_firmware, D7000v2_firmware, D7800_firmware, D8500_firmware, Dc112a_firmware, Dgn2200bv4_firmware, Dgn2200v4_firmware, Dm200_firmware, Ex3700_firmware, Ex3800_firmware, Ex6120_firmware, Ex6130_firmware, Ex7000_firmware, Pr2000_firmware, R6220_firmware, R6230_firmware, R6250_firmware, R6300v2_firmware, R6400_firmware, R6400v2_firmware, R6700_firmware, R6700v3_firmware, R6900_firmware, R7000_firmware, R7100lg_firmware, R7500v2_firmware, R7900p_firmware, R8000p_firmware, R8900_firmware, R9000_firmware, Rbk20_firmware, Rbk40_firmware, Rbk50_firmware, Rbr20_firmware, Rbr40_firmware, Rbr50_firmware, Rbs20_firmware, Rbs40_firmware, Rbs50_firmware, Wn3000rpv2_firmware, Wndr3400v3_firmware, Wnr2000v5_firmware, Wnr2020_firmware, Xr500_firmware 8.8
2023-03-29 CVE-2022-27642 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-15854. Cax80_firmware, Lax20_firmware, Mr60_firmware, Mr80_firmware, Ms60_firmware, Ms80_firmware, R6400_firmware, R6700_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7850_firmware, R7900p_firmware, R7960p_firmware, R8000_firmware, R8000p_firmware, R8500_firmware, Rax15_firmware, Rax200_firmware, Rax20_firmware, Rax35_firmware, Rax38_firmware, Rax40_firmware, Rax42_firmware, Rax43_firmware, Rax45_firmware, Rax48_firmware, Rax50_firmware, Rax50s_firmware, Rax75_firmware, Rax80_firmware, Rs400_firmware 8.8
2023-03-29 CVE-2022-27643 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SOAP requests. When parsing the SOAPAction header, the process does not properly validate the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to execute code in the context of... D6220_firmware, D6400_firmware, D7000v2_firmware, Dc112a_firmware, Ex3700_firmware, Ex3800_firmware, Ex6120_firmware, Ex6130_firmware, R6400_firmware, R6700_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7850_firmware, R7900p_firmware, R7960p_firmware, R8000_firmware, R8000p_firmware, R8500_firmware, Rax200_firmware, Rax75_firmware, Rax80_firmware, Rs400_firmware, Wndr3400_firmware, Wnr3500l_firmware, Xr300_firmware 8.8
2023-03-29 CVE-2022-27647 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the name or email field provided to libreadycloud.so. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call.... Cax80_firmware, Lax20_firmware, Mr60_firmware, Mr80_firmware, Ms60_firmware, Ms80_firmware, R6400_firmware, R6700_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7850_firmware, R7900p_firmware, R7960p_firmware, R8000_firmware, R8000p_firmware, R8500_firmware, Rax15_firmware, Rax200_firmware, Rax20_firmware, Rax35_firmware, Rax38_firmware, Rax40_firmware, Rax42_firmware, Rax43_firmware, Rax45_firmware, Rax48_firmware, Rax50_firmware, Rax50s_firmware, Rax75_firmware, Rax80_firmware, Rs400_firmware 8.0
2023-08-07 CVE-2023-38928 Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi. R7100lg_firmware 9.8
2016-12-14 CVE-2016-6277 NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/. D6220_firmware, D6400_firmware, R6250_firmware, R6400_firmware, R6700_firmware, R6900_firmware, R7000_firmware, R7100lg_firmware, R7300dst_firmware, R7900_firmware, R8000_firmware 8.8
2020-04-15 CVE-2020-11770 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, R6220 before 1.1.0.80, R6250 before 1.0.4.34, R6260 before 1.1.0.64, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6700v3 before 1.0.2.66, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before 1.3.1.64, R6900v2 before 1.2.0.36, R7000 before 1.0.9.42,... D6220_firmware, D6400_firmware, D7000_firmware, D8500_firmware, R6220_firmware, R6250_firmware, R6260_firmware, R6400_firmware, R6700_firmware, R6800_firmware, R6900_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7300dst_firmware, R7800_firmware, R7900_firmware, R7900p_firmware, R8000_firmware, R8000p_firmware, R8300_firmware, R8500_firmware, R8900_firmware, R9000_firmware, Xr500_firmware 8.8
2020-05-05 CVE-2017-18864 Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects R6400 before 1.0.1.24, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000 before 1.0.9.4, R7000P before 1.0.0.56, R6900P before 1.0.0.56, R7100LG before 1.0.0.32, R7300 before 1.0.0.54, R7900 before 1.0.1.18, R8300 before 1.0.2.104, and R8500 before 1.0.2.104. R6400_firmware, R6700_firmware, R6900_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7300_firmware, R7900_firmware, R8300_firmware, R8500_firmware N/A
2020-05-05 CVE-2017-18867 Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55, D7800 before V1.0.1.24, R7100LG before V1.0.0.32, WNDR4300v1 before 1.0.2.90, and WNDR4500v3 before 1.0.0.48. D6100_firmware, D7800_firmware, R7100lg_firmware, Wndr4300_firmware, Wndr4500_firmware N/A