Corega manufactures consumer and small-business networking devices, primarily routers and wireless access points, with a concentrated product portfolio spanning models such as the CG-WGR1200 and CG-WLR300NX. Its vulnerability profile centers on web-interface and firmware-level weaknesses including buffer-boundary issues, cross-site request forgery, cross-site scripting, improper access controls, and input-validation flaws that are characteristic of embedded network appliances. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Corega over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7811HIGH Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vector | Jun 9, 2017 | 8.8 | 26 | NO | NO |
CVE-2015-7792CRITICAL Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors. | Dec 30, 2015 | 9.8 | 26 | NO | NO |
CVE-2016-4822HIGH Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors. | Jun 25, 2016 | 8.0 | 25 | NO | NO |
CVE-2017-10854HIGH Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors. | Mar 9, 2018 | 8.8 | 24 | NO | NO |
CVE-2016-4823HIGH Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors. | Jun 25, 2016 | 7.5 | 24 | NO | NO |
CVE-2017-10853HIGH Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors. | Mar 9, 2018 | 8.8 | 22 | NO | NO |
CVE-2017-10852HIGH Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors. | Mar 9, 2018 | 8.8 | 22 | NO | NO |
CVE-2017-10814MEDIUM Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors. | Sep 15, 2017 | 6.8 | 22 | NO | NO |
CVE-2016-7809HIGH Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to condu | Jun 9, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-7808MEDIUM Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jun 9, 2017 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Corega.
Media articles that mention a CVE ID that affects a product developed by Corega — matched by CVE ID, not by vendor name.