Home/Product/netgear r7960p firmware
Product

netgear r7960p firmware

46 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-34983
< 1.4.2.84
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerabili
6.5MEDIUM
CVE-2021-34982
< 1.4.2.84
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-
8.8HIGH
CVE-2022-27647
< 1.4.3.88
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.
8.0HIGH
CVE-2022-27646
< 1.4.3.88
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.
8.8HIGH
CVE-2022-27645
< 1.4.3.88
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers
8.8HIGH
CVE-2022-27644
< 1.4.3.88
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installatio
8.8HIGH
CVE-2022-27643
< 1.4.3.88
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.
8.8HIGH
CVE-2022-27642
< 1.4.3.88
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.1
8.8HIGH
CVE-2022-48322
< 1.4.4.94
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 bef
9.8CRITICAL
CVE-2022-48176
< 1.4.4.94
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were disc
7.8HIGH
CVE-2022-48196
< 1.4.4.94
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0.2.60, RAX3
7.4HIGH
CVE-2021-45668
< 1.4.1.66
Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0
6.5MEDIUM
CVE-2021-45667
< 1.4.1.66
Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.
6.5MEDIUM
CVE-2021-45647
< 1.4.1.66
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EAX80 before 1.0.1.62, EX7000 before 1.0
6.5MEDIUM
CVE-2021-45639
< 1.4.1.66
Certain NETGEAR devices are affected by reflected XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.32, EAX80 before 1.0
5.2MEDIUM
CVE-2021-45622
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45621
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45620
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45617
< 1.4.1.66
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX2
9.8CRITICAL
CVE-2021-45616
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX
9.6CRITICAL
CVE-2021-45615
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45612
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45610
< 1.4.1.64
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.66, D640
9.6CRITICAL
CVE-2021-45606
< 1.4.2.84
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6400 before 1.0.1.70
4.5MEDIUM
CVE-2021-45604
< 1.4.2.84
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.
4.5MEDIUM
CVE-2021-45555
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P be
8.4HIGH
CVE-2021-45549
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 befor
8.4HIGH
CVE-2021-45547
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74, R7900P bef
8.4HIGH
CVE-2021-45546
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74, R7900P bef
8.4HIGH
CVE-2021-45545
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74, R7900P bef
8.4HIGH
CVE-2021-45544
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74, R7900P bef
8.4HIGH
CVE-2021-45540
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R7900 be
8.4HIGH
CVE-2021-45539
< 1.4.2.84
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P be
8.4HIGH
CVE-2021-45530
< 1.4.2.84
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R7000 before 1.0.11.126, R7960P b
4.5MEDIUM
CVE-2021-45527
< 1.4.1.68
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.68, D6400 befo
9.6CRITICAL
CVE-2021-45499
< 1.4.2.84
Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R790
8.2HIGH
CVE-2021-34991
< 1.4.2.84
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.
8.8HIGH
CVE-2021-38516
< 1.4.1.44
Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 be
10.0CRITICAL
CVE-2021-27239
< 1.4.1.68
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R670
8.8HIGH
CVE-2021-29080
< 1.4.1.66
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK85
8.1HIGH
CVE-2021-29073
< 1.4.1.66
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R8000P before 1.4.1.6
7.6HIGH
CVE-2021-29068
< 1.4.1.62
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2
9.9CRITICAL
CVE-2020-35800
< 1.4.1.62
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400
9.4CRITICAL
CVE-2020-35798
< 1.4.1.50
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6
9.3CRITICAL
CVE-2020-35796
< 1.4.1.62
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D622
8.8HIGH
CVE-2020-35795
< 1.4.1.62
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects AC2100 before 1.2.0.72, AC2
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin