NETGEAR Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for NETGEAR products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
15
In CISA KEV
8
Beyond CISA KEV
7
Sensor Observed
1
Virtual Patch Available
1
NETGEAR KEVs Added by Year
15 NETGEAR KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-20166
Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router... |
RAX43 | High | Not in CISA | 07 Jun 2026 |
|
CVE-2024-12847
NETGEAR DGN setup.cgi OS Command Injection |
DGN1000 | Confirmed | Not in CISA | 01 Jun 2026 |
|
CVE-2017-18378
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through... |
ReadyNAS Surveillance | High | Not in CISA | 04 Jun 2025 |
|
CVE-2022-40619
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected... |
Routers and Orbi WiFi Systems | High | Not in CISA | 28 Jan 2026 |
|
CVE-2025-7407
Netgear D6400 diag.cgi os command injection |
D6400 | High | Not in CISA | 10 Jul 2025 |
|
CVE-2022-29383
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at... |
ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 | High | Not in CISA | 22 Apr 2025 |
|
CVE-2016-5674
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1... |
["NVRmini 2", "NVRsolo", "ReadyNAS Surveillance"] | High | Not in CISA | 27 Apr 2025 |
|
CVE-2020-26919
NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. |
JGS516PE | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-6277
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before... |
Routers | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2017-6077
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell... |
DGN2200 | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2016-10174
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This... |
WNR2000v5 router | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-1555
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and... |
WN604, WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, WNDAP660 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-6334
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via... |
DGN2200 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-6862
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and... |
NETGEAR All versions prior to WNR2000v3 1.1.2.14, WNR2000v4 1.0.0.66, WNR2000v5 1.0.0.42 | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2017-5521
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000... |
Routers | Confirmed | In CISA | 08 Sep 2022 |
Common Vulnerability Classes (CWE)
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 4
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-120 — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') 3
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
- CWE-352 — Cross-Site Request Forgery (CSRF) 1
- CWE-20 — Improper Input Validation 1
- CWE-306 — Missing Authentication for Critical Function 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology