Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

NETGEAR

First CVE: Jul 21, 2001Active for: 25 yearsTotal CVEs: 1,335
56.0
VTI Score
TOP TARGET

NETGEAR's vulnerability footprint spans a very broad portfolio of consumer and small-business networking devices—routers, wireless access points, and storage appliances—that are widely deployed across residential and enterprise edge networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure concentrates in flagship router lines such as the R7800 and R9000 and their associated firmware, where it recurs through command-injection, cross-site scripting, out-of-bounds write, and classic buffer-overflow weakness classes that are endemic to embedded network device firmware. These weakness patterns reflect the parsing and memory-safety challenges of handling diverse network protocols and web-management interfaces in constrained device firmware. Defenders should prioritize inventory and patching of internet-exposed NETGEAR devices, especially older models that may be out of support, since firmware updates are often difficult to enforce across distributed deployments. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,335
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by NETGEAR over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 21, 2001
25 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Self-Reporting Analysis

Of all the CVEs published by NETGEAR as a CNA, 84.2% affect products that NETGEAR develops as a vendor.

84.2%
15.8%
Self-reported: 32 (84.2%)
Third-party: 6 (15.8%)

Of all the CVEs published that affect products developed by NETGEAR, 2.4% are self-published by NETGEAR as a CNA.

97.6%
Self-published: 32 (2.4%)
Other CNAs: 1,303 (97.6%)

Products(1,110 total)

Top CVEs

Signals from CVEs in this vendor scope (1335 CVEs).

1,335 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-1555CRITICAL
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP3
Apr 21, 20179.899YESYES
CVE-2016-6277HIGH
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.
Dec 14, 20168.899YESYES
CVE-2017-5521HIGH
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password d
Jan 17, 20178.198YESYES
CVE-2016-10174CRITICAL
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by
Jan 30, 20179.897YESYES
CVE-2017-6334HIGH
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_nam
Mar 6, 20178.896YESYES
CVE-2017-6077CRITICAL
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr f
Feb 22, 20179.895YESYES
CVE-2020-26919CRITICAL
NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.
Oct 9, 20209.893YESYES
CVE-2016-5674CRITICAL
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke
Aug 31, 20169.893NOYES
CVE-2016-1524CRITICAL
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUp
Feb 13, 20169.690NOYES
CVE-2017-6862CRITICAL
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buff
May 26, 20179.886YESNO
View all 1,335 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,335 CVEs
42%
43%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local92 (6.9%)
Network617 (46.2%)
Unknown48 (3.6%)
Physical10 (0.7%)
Adjacent Network568 (42.5%)
Attack Complexity
Low1,257 (94.2%)
High30 (2.2%)
Unknown48 (3.6%)
User Interaction
None1,069 (80.1%)
Unknown48 (3.6%)
Required218 (16.3%)
Privileges Required
Low242 (18.1%)
High401 (30.0%)
None644 (48.2%)
Unknown48 (3.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (1335 CVEs).

CISA KEV
8 CVEs
0.6% of CVEs· 99th percentile
Metasploit
23 CVEs
1.7% of CVEs· 97th percentile
Nuclei
13 CVEs
1.0% of CVEs· 95th percentile
ExploitDB
32 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by NETGEAR.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by NETGEAR — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For NETGEAR's Products

View all 11 CNAs →

Top CWEs