R2000 Firmware

Vendor:

First CVE: Jan 30, 2017 · Active for 9 years

2
Total CVEs
More Total CVEs than 53% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
50.0%
KEV Rate
Higher KEV Rate than 99% of tracked products

Trends Over Time

The number and severity of CVEs published that impact R2000 Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2017
9 years ago
Most Recent CVE
Apr 28, 2020
2,282 days ago

CVE Severity & Scoring

R2000 Firmware2 CVEs
All CVEs353,240 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by
Jan 30, 20179.897YESYES
Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-06, D500 before 2017-01-06, D1500 before 2017-01-06, D3600 be
Apr 28, 20207.519NONO

Exploit Exposure

Signals from CVEs in this product scope (2 CVEs).

CISA KEV
1 CVE
50.0% of CVEs· 99th percentile
Metasploit
1 CVE
50.0% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
50.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (2 CVEs).

Media Mentions

Signals from CVEs in this product scope (2 CVEs).

Top CNAs Publishing CVEs For R2000 Firmware

Top CWEs

Versions

No cataloged versions.