Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Xr300_firmware
(Netgear)| Repositories |
Unknown: This might be proprietary software. |
| #Vulnerabilities | 55 |
| Date | Id | Summary | Products | Score | Patch | Annotated |
|---|---|---|---|---|---|---|
| 2024-11-05 | CVE-2024-51002 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | R6400v2_firmware, R7000p_firmware, R8500_firmware, Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-51007 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-51008 | Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-51014 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid_an parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-51016 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-51022 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-52017 | Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Xr300_firmware | N/A | ||
| 2024-11-05 | CVE-2024-52018 | Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request. | Xr300_firmware | N/A | ||
| 2020-05-28 | CVE-2020-13245 | Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P. | R6120_firmware, R6220_firmware, R6350_firmware, R6400_firmware, R6800_firmware, R6850_firmware, R7000p_firmware, R7800_firmware, R8000_firmware, R9000_firmware, Rax120_firmware, Rbr20_firmware, Xr300_firmware, Xr500_firmware | 5.9 | ||
| 2020-11-09 | CVE-2020-28373 | upnpd on certain NETGEAR devices allows remote (LAN) attackers to execute arbitrary code via a stack-based buffer overflow. This affects R6400v2 V1.0.4.102_10.0.75, R6400 V1.0.1.62_1.0.41, R7000P V1.3.2.126_10.1.66, XR300 V1.0.3.50_10.3.36, R8000 V1.0.4.62, R8300 V1.0.2.136, R8500 V1.0.2.136, R7300DST V1.0.0.74, R7850 V1.0.5.64, R7900 V1.0.4.30, RAX20 V1.0.2.64, RAX80 V1.0.3.102, and R6250 V1.0.4.44. | R6250_firmware, R6400_firmware, R6400v2_firmware, R7000p_firmware, R7300dst_firmware, R7850_firmware, R7900_firmware, R8000_firmware, R8300_firmware, R8500_firmware, Rax20_firmware, Rax80_firmware, Xr300_firmware | 8.8 |