Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Wnr2000v5_firmware
(Netgear)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 14 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-12-26 | CVE-2021-45641 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1.1.00.34, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.74, D7000v2 before 1.0.0.53, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200Bv4 before 1.0.0.109, DGN2200v4 before 1.0.0.110, DM200 before 1.0.0.61, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6120 before 1.0.0.46, EX6130... | D3600_firmware, D6000_firmware, D6200_firmware, D6220_firmware, D6400_firmware, D7000_firmware, D7000v2_firmware, D7800_firmware, D8500_firmware, Dc112a_firmware, Dgn2200bv4_firmware, Dgn2200v4_firmware, Dm200_firmware, Ex3700_firmware, Ex3800_firmware, Ex6120_firmware, Ex6130_firmware, Ex7000_firmware, Pr2000_firmware, R6220_firmware, R6230_firmware, R6250_firmware, R6300v2_firmware, R6400_firmware, R6400v2_firmware, R6700_firmware, R6700v3_firmware, R6900_firmware, R7000_firmware, R7100lg_firmware, R7500v2_firmware, R7900p_firmware, R8000p_firmware, R8900_firmware, R9000_firmware, Rbk20_firmware, Rbk40_firmware, Rbk50_firmware, Rbr20_firmware, Rbr40_firmware, Rbr50_firmware, Rbs20_firmware, Rbs40_firmware, Rbs50_firmware, Wn3000rpv2_firmware, Wndr3400v3_firmware, Wnr2000v5_firmware, Wnr2020_firmware, Xr500_firmware | 8.8 | ||
2021-12-26 | CVE-2021-45658 | Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1.78, EX6250 before 1.0.0.110, EX6410 before 1.0.0.110, EX6420 before 1.0.0.110, EX6400v2 before 1.0.0.110, EX7300 before 1.0.2.144, EX6400 before 1.0.2.144, EX7320 before 1.0.0.110, EX7300v2 before 1.0.0.110, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before... | D7800_firmware, Dm200_firmware, Ex2700_firmware, Ex6100v2_firmware, Ex6150v2_firmware, Ex6200v2_firmware, Ex6250_firmware, Ex6400_firmware, Ex6400v2_firmware, Ex6410_firmware, Ex6420_firmware, Ex7300_firmware, Ex7300v2_firmware, Ex7320_firmware, R7500v2_firmware, R7800_firmware, R8900_firmware, R9000_firmware, Rax120_firmware, Rbk20_firmware, Rbk40_firmware, Rbk50_firmware, Rbr20_firmware, Rbr50_firmware, Rbs20_firmware, Rbs50_firmware, Rbs50y_firmware, Wn3000rpv2_firmware, Wn3000rpv3_firmware, Wnr2000v5_firmware, Xr500_firmware, Xr700_firmware | 9.8 | ||
2017-01-30 | CVE-2016-10176 | The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL, apply_noauth.cgi, that allows an unauthenticated user to perform sensitive actions on the device. This functionality can be exploited to change the router settings (such as the answers to the password-recovery... | Wnr2000v5_firmware | 9.8 | ||
2017-01-30 | CVE-2016-10175 | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions. | Wnr2000v5_firmware | 9.8 |