Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Wnr1000_firmware
(Netgear)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 36 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-04-22 | CVE-2017-18785 | Certain NETGEAR devices are affected by XSS. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D6200 before 1.1.00.24, D6220 before 1.0.0.32, D6400 before 1.0.0.66, D7000 before 1.0.1.52, D7000v2 before 1.0.0.44, D7800 before 1.0.1.30, D8500 before 1.0.3.35, DGN2200v4 before 1.0.0.96, DGN2200Bv4 before 1.0.0.96, EX2700 before 1.0.1.28, EX6100v2 before 1.0.1.54, EX6150v2 before 1.0.1.54, EX6200v2 before 1.0.1.52, EX6400 before 1.0.1.72, EX7300 before 1.0.1.72,... | D3600_firmware, D6000_firmware, D6100_firmware, D6200_firmware, D6220_firmware, D6400_firmware, D7000_firmware, D7800_firmware, D8500_firmware, Dgn2200_firmware, Dgn2200b_firmware, Ex2700_firmware, Ex6100_firmware, Ex6150_firmware, Ex6200_firmware, Ex6400_firmware, Ex7300_firmware, Ex8000_firmware, Jnr1010_firmware, Jwnr2010_firmware, Pr2000_firmware, R6020_firmware, R6080_firmware, R6100_firmware, R6250_firmware, R6300_firmware, R6400_firmware, R6700_firmware, R6800_firmware, R6900_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7300dst_firmware, R7500_firmware, R7800_firmware, R7900_firmware, R7900p_firmware, R8000_firmware, R8000p_firmware, R8300_firmware, R8500_firmware, R9000_firmware, Wn2000rpt_firmware, Wn3000rp_firmware, Wn3100rp_firmware, Wndr3400_firmware, Wndr3700_firmware, Wndr4300_firmware, Wndr4500_firmware, Wnr1000_firmware, Wnr2000_firmware, Wnr2020_firmware, Wnr2050_firmware, Wnr3500l_firmware | N/A | ||
2020-04-23 | CVE-2017-18737 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44. | Jnr1010_firmware, Jr6150_firmware, Jwnr2010_firmware, Pr2000_firmware, R6050_firmware, R6220_firmware, R6700_firmware, R6800_firmware, R6900_firmware, Wndr3700_firmware, Wnr1000_firmware, Wnr2020_firmware, Wnr2050_firmware | N/A | ||
2020-04-23 | CVE-2017-18734 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44. | Jnr1010_firmware, Jr6150_firmware, Jwnr2010_firmware, Pr2000_firmware, R6050_firmware, R6220_firmware, R6700_firmware, R6800_firmware, R6900_firmware, Wndr3700_firmware, Wnr1000_firmware, Wnr2020_firmware, Wnr2050_firmware | N/A | ||
2020-03-02 | CVE-2019-20489 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a cookie, reads the Set-Cookie header in the 401 Unauthorized response, and then repeats the FW_remote.htm&todo=cfg_init request with the specified cookie. | Wnr1000_firmware | N/A | ||
2020-03-02 | CVE-2019-20488 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter. | Wnr1000_firmware | N/A | ||
2020-03-02 | CVE-2019-20487 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI. | Wnr1000_firmware | N/A | ||
2020-03-02 | CVE-2019-20486 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language. | Wnr1000_firmware | N/A | ||
2020-01-29 | CVE-2013-3317 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key. | Wnr1000_firmware | N/A | ||
2020-01-29 | CVE-2013-3316 | Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg". | Wnr1000_firmware | N/A | ||
2019-10-09 | CVE-2019-17372 | Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanChanged.cgi. The attacker can then, for example, visit MNU_accessPassword_recovered.html to obtain a valid new admin password. This affects AC1450, D8500, DC112A, JNDR3000, LG2200D, R4500, R6200, R6200V2, R6250, R6300, R6300v2, R6400, R6700, R6900P, R6900, R7000P, R7000, R7100LG, R7300, R7900, R8000, R8300, R8500, WGR614v10, WN2500RPv2, WNDR3400v2, WNDR3700v3, WNDR4000,... | Ac1450_firmware, D8500_firmware, Dc112a_firmware, Jndr3000_firmware, Lg2200d_firmware, R4500_firmware, R6200_firmware, R6200v2_firmware, R6250_firmware, R6300_firmware, R6300v2_firmware, R6400_firmware, R6700_firmware, R6900_firmware, R6900p_firmware, R7000_firmware, R7000p_firmware, R7100lg_firmware, R7300_firmware, R7900_firmware, R8000_firmware, R8300_firmware, R8500_firmware, Wgr614v10_firmware, Wn2500rpv2_firmware, Wndr3400v2_firmware, Wndr3700v3_firmware, Wndr4000_firmware, Wndr4500_firmware, Wndr4500v2_firmware, Wnr1000_firmware, Wnr1000v3_firmware, Wnr3500l_firmware | N/A |