Home/Product/netgear xr1000 firmware
Product

netgear xr1000 firmware

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-35517
all versions
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
8.4HIGH
CVE-2021-34983
< 1.0.0.64
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerabili
6.5MEDIUM
CVE-2021-34982
< 1.0.0.64
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-
8.8HIGH
CVE-2021-45654
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by disclosure of sensitive information.
9.6CRITICAL
CVE-2021-45643
< 1.0.0.58
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6400v2 before 1.0.4.118, R6700
8.2HIGH
CVE-2021-45622
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45621
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45620
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45616
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX
9.6CRITICAL
CVE-2021-45614
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LA
9.6CRITICAL
CVE-2021-45613
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45612
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR7
9.6CRITICAL
CVE-2021-45604
< 1.0.0.58
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.
4.5MEDIUM
CVE-2021-45549
< 1.0.0.58
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 befor
8.4HIGH
CVE-2021-45522
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.
6.1MEDIUM
CVE-2021-45519
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
6.5MEDIUM
CVE-2021-45518
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
6.5MEDIUM
CVE-2021-45517
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by denial of service.
6.5MEDIUM
CVE-2021-45514
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
9.6CRITICAL
CVE-2021-45513
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.
9.6CRITICAL
CVE-2021-45510
< 1.0.0.58
NETGEAR XR1000 devices before 1.0.0.58 are affected by authentication bypass.
8.2HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin