NETGEAR's vulnerability footprint spans a very broad portfolio of consumer and small-business networking devices—routers, wireless access points, and storage appliances—that are widely deployed across residential and enterprise edge networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure concentrates in flagship router lines such as the R7800 and R9000 and their associated firmware, where it recurs through command-injection, cross-site scripting, out-of-bounds write, and classic buffer-overflow weakness classes that are endemic to embedded network device firmware. These weakness patterns reflect the parsing and memory-safety challenges of handling diverse network protocols and web-management interfaces in constrained device firmware. Defenders should prioritize inventory and patching of internet-exposed NETGEAR devices, especially older models that may be out of support, since firmware updates are often difficult to enforce across distributed deployments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by NETGEAR over time
Of all the CVEs published by NETGEAR as a CNA, 84.2% affect products that NETGEAR develops as a vendor.
Of all the CVEs published that affect products developed by NETGEAR, 2.4% are self-published by NETGEAR as a CNA.
Signals from CVEs in this vendor scope (1335 CVEs).
1,335 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1555CRITICAL (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP3 | Apr 21, 2017 | 9.8 | 99 | YES | YES |
CVE-2016-6277HIGH NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46. | Dec 14, 2016 | 8.8 | 99 | YES | YES |
CVE-2017-5521HIGH An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password d | Jan 17, 2017 | 8.1 | 98 | YES | YES |
CVE-2016-10174CRITICAL The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by | Jan 30, 2017 | 9.8 | 97 | YES | YES |
CVE-2017-6334HIGH dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_nam | Mar 6, 2017 | 8.8 | 96 | YES | YES |
CVE-2017-6077CRITICAL ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr f | Feb 22, 2017 | 9.8 | 95 | YES | YES |
CVE-2020-26919CRITICAL NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. | Oct 9, 2020 | 9.8 | 93 | YES | YES |
CVE-2016-5674CRITICAL __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke | Aug 31, 2016 | 9.8 | 93 | NO | YES |
CVE-2016-1524CRITICAL Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUp | Feb 13, 2016 | 9.6 | 90 | NO | YES |
CVE-2017-6862CRITICAL NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buff | May 26, 2017 | 9.8 | 86 | YES | NO |
Signals from CVEs in this vendor scope (1335 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by NETGEAR.
Media articles that mention a CVE ID that affects a product developed by NETGEAR — matched by CVE ID, not by vendor name.