NETGEAR

First CVE: May 26, 2017Active for: 9 years
38
CVEs Published
More CVEs Published than 52% of tracked CNAs
9.5
Avg CVEs / Year
More Avg CVEs / Year than 52% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked CNAs
2.6%
In CISA KEV
Higher KEV Rate than 93% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by NETGEAR as a CNA, 84.2% affect products that NETGEAR develops as a vendor.

84.2%
15.8%
Self-reported: 32Third-party: 6

Of all the CVEs published that affect products developed by NETGEAR, 2.4% are self-published by NETGEAR as a CNA.

97.6%
Self-published: 32Published by other CNAs: 1,303

Trends Over Time

The number and severity of CVEs published by NETGEAR over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2017
9 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by NETGEAR as a CNA, regardless of affected vendor or product.

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buff
May 26, 20179.886YESNO
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
Jun 9, 20268.833NONO
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operati
Jun 9, 20268.031NONO
NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versio
Apr 1, 20209.831NONO
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code o
Jun 9, 20268.130NONO
A security flaw was discovered in the NETGEAR DGND3700v1 that could allow someone on the same local WiFi network to send unauthorized commands to the device. This issue was iden
Jul 14, 20266.329NONO
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality
Jun 9, 20268.029NONO
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi ro
Jun 9, 20268.029NONO
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to
Jan 13, 20268.029NONO
A security flaw was found in certain NETGEAR Orbi models that could allow an unauthorized user to cause the device to stop responding or restart unexpectedly, disrupting network co
Jul 14, 20265.728NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA38 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (5.3%)
Network6 (15.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network24 (63.2%)
Attack Complexity
Low31 (81.6%)
High7 (18.4%)
Unknown0 (0.0%)
User Interaction
None37 (97.4%)
Unknown0 (0.0%)
Required1 (2.6%)
Privileges Required
Low11 (28.9%)
High14 (36.8%)
None13 (34.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (38 CVEs).

CISA KEV
1 CVE
2.6% of CVEs· 93rd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by NETGEAR as a CNA.

Media Mentions

Media articles that mention a CVE ID published by NETGEAR as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs