Product:

Wnr2000_firmware

(Netgear)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 92
Date Id Summary Products Score Patch Annotated
2022-12-20 CVE-2022-46423 An exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v1.2.3.7 and earlier. Wnr2000_firmware 8.1
2023-12-15 CVE-2023-50089 A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication. Wnr2000_firmware 9.8
2019-09-11 CVE-2019-5054 An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability. Wnr2000_firmware 7.5
2019-09-11 CVE-2019-5055 An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in an invalid sequence to the <WFAWLANConfig:1#PutMessage> service can cause a null pointer dereference, resulting in the hostapd service crashing. An unauthenticated attacker can send a specially-crafted SOAP request to trigger this vulnerability. Wnr2000_firmware 7.5
2020-04-16 CVE-2019-20688 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.72, EX6400 before 1.0.2.136, EX7300 before 1.0.2.136, EX8000 before 1.0.1.180, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, WN2000RPTv3 before 1.0.1.32, WN3000RPv2 before 1.0.0.68, WN3100RPv2 before 1.0.0.60,... D3600_firmware, D6000_firmware, D6100_firmware, Ex2700_firmware, Ex6100_firmware, Ex6150_firmware, Ex6200_firmware, Ex6400_firmware, Ex7300_firmware, Ex8000_firmware, R7800_firmware, R8900_firmware, R9000_firmware, Wn2000rpt_firmware, Wn3000rp_firmware, Wn3100rp_firmware, Wndr3700_firmware, Wndr4300_firmware, Wndr4500_firmware, Wnr2000_firmware, Xr500_firmware 6.8
2020-04-16 CVE-2019-20689 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.1.72, EX6400 before 1.0.2.136, EX7300 before 1.0.2.136, EX8000 before 1.0.1.180, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, WN2000RPTv3 before 1.0.1.32, WN3000RPv2 before 1.0.0.68, WN3100RPv2 before 1.0.0.60, WNDR3700v4 before... D6000_firmware, D6100_firmware, Ex2700_firmware, Ex6100_firmware, Ex6150_firmware, Ex6200_firmware, Ex6400_firmware, Ex7300_firmware, Ex8000_firmware, R7800_firmware, R8900_firmware, R9000_firmware, Wn2000rpt_firmware, Wn3000rp_firmware, Wn3100rp_firmware, Wndr3700_firmware, Wndr4300_firmware, Wndr4500_firmware, Wnr2000_firmware, Xr500_firmware 6.8
2020-04-24 CVE-2017-18703 Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, EX6100v2 before 1.0.1.60, EX6150v2 before 1.0.1.60, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.16, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.18, R6020 before 1.0.0.26, R6050 before 1.0.1.16, R6080 before 1.0.0.26, R6100 before 1.0.1.20, R6220 before 1.1.0.60, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20,... D1500_firmware, D500_firmware, D6100_firmware, D7000_firmware, D7800_firmware, Ex6100_firmware, Ex6150_firmware, Jnr1010_firmware, Jr6150_firmware, Jwnr2010_firmware, Pr2000_firmware, R6020_firmware, R6050_firmware, R6080_firmware, R6100_firmware, R6220_firmware, R7500_firmware, R7800_firmware, R9000_firmware, Wn3000rp_firmware, Wn3100rp_firmware, Wndr3700_firmware, Wndr4300_firmware, Wndr4500_firmware, Wnr1000_firmware, Wnr2000_firmware, Wnr2020_firmware, Wnr2050_firmware N/A
2020-05-05 CVE-2017-18866 Certain NETGEAR devices are affected by stored XSS. This affects R9000 before 1.0.2.40, R6100 before 1.0.1.1, 6R7500 before 1.0.0.110, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, WNDR4300v2 before 1.0.0.48, and WNR2000v5 before 1.0.0.58. 6r7500_firmware, R6100_firmware, R7500_firmware, R7800_firmware, R9000_firmware, Wndr4300_firmware, Wnr2000_firmware N/A
2020-04-27 CVE-2018-21155 Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.52, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, R7800 before 1.0.2.42, R8900 before 1.0.4.2, R9000 before 1.0.3.16, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64. D7800_firmware, Dm200_firmware, R6100_firmware, R7500_firmware, R7800_firmware, R8900_firmware, R9000_firmware, Wndr4300_firmware, Wndr4500_firmware, Wnr2000_firmware N/A
2020-04-27 CVE-2018-21149 Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.0.54, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64. D7800_firmware, Dm200_firmware, R6100_firmware, R7500_firmware, R7800_firmware, R8900_firmware, R9000_firmware, Wndr3700_firmware, Wndr4300_firmware, Wndr4500_firmware, Wnr2000_firmware N/A