NETGEAR vendor intelligence
NETGEAR Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting NETGEAR products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 15
- Known exploited vulnerabilities affecting NETGEAR products
- In CISA KEV
- 8
- Records also listed in the official catalog
- Beyond CISA KEV
- 7
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- NETGEAR KEV with sensor-observed exploitation activity
The catalog gap matters for NETGEAR exposure
Seven of the fifteen exploited NETGEAR CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 47% of this vendor portfolio.
- 53%
- Covered by CISA
- 47%
- Beyond CISA
- 13
- Product families
Attested NETGEAR CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-20166
Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router... |
RAX43 | High | Beyond CISA | 07 Jun 2026 |
|
CVE-2024-12847
NETGEAR DGN setup.cgi OS Command Injection |
DGN1000 | Confirmed | Beyond CISA | 01 Jun 2026 |
|
CVE-2017-18378
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through... |
ReadyNAS Surveillance | High | Beyond CISA | 04 Jun 2025 |
|
CVE-2022-40619
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected... |
Routers and Orbi WiFi Systems | High | Beyond CISA | 28 Jan 2026 |
|
CVE-2025-7407
Netgear D6400 diag.cgi os command injection |
D6400 | High | Beyond CISA | 10 Jul 2025 |
|
CVE-2022-29383
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at... |
ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 | High | Beyond CISA | 22 Apr 2025 |
|
CVE-2016-5674
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1... |
["NVRmini 2", "NVRsolo", "ReadyNAS Surveillance"] | High | Beyond CISA | 27 Apr 2025 |
|
CVE-2020-26919
NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. |
JGS516PE | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2016-6277
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before... |
Routers | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2017-6077
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell... |
DGN2200 | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2016-10174
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This... |
WNR2000v5 router | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-1555
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and... |
WN604, WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, WNDAP660 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-6334
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via... |
DGN2200 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-6862
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and... |
NETGEAR All versions prior to WNR2000v3 1.1.2.14, WNR2000v4 1.0.0.66, WNR2000v5 1.0.0.42 | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2017-5521
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000... |
Routers | Confirmed | In CISA | 08 Sep 2022 |
No NETGEAR CVEs match this search or filter.
Showing 15 of 15 NETGEAR known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, neutralization, and buffer copy without checking size account for eleven mapped occurrences across this NETGEAR KEV portfolio.
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-352
Cross-Site Request Forgery (CSRF)
CWE-20
Improper Input Validation
CWE-306
Missing Authentication for Critical Function
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.