NETGEAR
First CVE: May 26, 2017Active for: 9 years
38
CVEs Published
More CVEs Published than 52% of tracked CNAs
9.5
Avg CVEs / Year
More Avg CVEs / Year than 52% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked CNAs
2.6%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by NETGEAR as a CNA, 84.2% affect products that NETGEAR develops as a vendor.
84.2%
15.8%
Self-reported: 32Third-party: 6
Of all the CVEs published that affect products developed by NETGEAR, 2.4% are self-published by NETGEAR as a CNA.
97.6%
Self-published: 32Published by other CNAs: 1,303
Trends Over Time
The number and severity of CVEs published by NETGEAR over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2017
9 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by NETGEAR as a CNA, regardless of affected vendor or product.
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6862CRITICAL NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buff | May 26, 2017 | 9.8 | 86 | YES | NO |
CVE-2026-9211HIGH An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation. | Jun 9, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-0419HIGH Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operati | Jun 9, 2026 | 8.0 | 31 | NO | NO |
CVE-2018-11106CRITICAL NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versio | Apr 1, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-9213HIGH A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code o | Jun 9, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-15757MEDIUM A security flaw was discovered in the NETGEAR DGND3700v1 that could
allow someone on the same local WiFi network to send unauthorized commands to
the device.
This issue was iden | Jul 14, 2026 | 6.3 | 29 | NO | NO |
CVE-2026-9212HIGH Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality | Jun 9, 2026 | 8.0 | 29 | NO | NO |
CVE-2026-0411HIGH An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi ro | Jun 9, 2026 | 8.0 | 29 | NO | NO |
CVE-2026-0407HIGH An insufficient authentication vulnerability in NETGEAR WiFi range
extenders allows a network adjacent attacker with WiFi authentication or
a physical Ethernet port connection to | Jan 13, 2026 | 8.0 | 29 | NO | NO |
CVE-2026-62655MEDIUM A
security flaw was found in certain NETGEAR Orbi models that
could allow an unauthorized user to cause the device to stop responding or
restart unexpectedly, disrupting network co | Jul 14, 2026 | 5.7 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA38 CVEs
53%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.3%)
Network6 (15.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network24 (63.2%)
Attack Complexity
Low31 (81.6%)
High7 (18.4%)
Unknown0 (0.0%)
User Interaction
None37 (97.4%)
Unknown0 (0.0%)
Required1 (2.6%)
Privileges Required
Low11 (28.9%)
High14 (36.8%)
None13 (34.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (38 CVEs).
CISA KEV
1 CVE
2.6% of CVEs· 93rd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by NETGEAR as a CNA.
Media Mentions
Media articles that mention a CVE ID published by NETGEAR as a CNA — matched by CVE ID, not by organization name.