CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2018-21136

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

    Published: 23 Apr 2020
    7.2
    High

    CVE-2018-21135

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700 before 1.0.1.48, R7500 before 1.0.0.124, R7800 before 1.0.2.58, R8900 before 1.0.4.2, R9000 before 1.0.4.2, WNDR3700v4 before 1.0.2.102, WNDR4300v1 before 1.0.2.104, WNDR4300v2 before 1.0.0.56, WNDR4500v3 before 1.0.0.56, and WNR2000v5-R2000 before 1.0.0.68.

    Published: 23 Apr 2020
    9.8
    Critical

    CVE-2018-21134

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6700 before 1.0.1.48, R7900 before 1.0.2.16, R6900 before 1.0.1.48, R7000P before 1.3.1.44, R6900P before 1.3.1.44, R6250 before 1.0.4.30, R6300v2 before 1.0.4.32, R6400 before 1.0.1.44, R6400v2 before 1.0.2.60, R7000 before 1.0.9.34, R7100LG before 1.0.0.48, R7300 before 1.0.0.68, R8000 before 1.0.4.18, R8000P before 1.4.1.24, R7900P before 1.4.1.24, R8500 before 1.0.2.122, R8300 before 1.0.2.122, WN2500RPv2 before 1.0.1.54, EX3700 before 1.0.0.72, EX3800 before 1.0.0.72, EX6000 before 1.0.0.32, EX6100 before 1.0.2.24, EX6120 before 1.0.0.42, EX6130 before 1.0.0.24, EX6150v1 before 1.0.0.42, EX6200 before 1.0.3.88, EX7000 before 1.0.0.66, D7000v2 before 1.0.0.51, D6220 before 1.0.0.46, D6400 before 1.0.0.82, and D8500 before 1.0.3.42.

    Published: 23 Apr 2020
    5.5
    Medium

    CVE-2020-12458

    Last Modified: 21 Nov 2024

    An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

    Published: 23 Apr 2020
    5.5
    Medium

    CVE-2020-12459

    Last Modified: 21 Nov 2024

    In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

    Published: 23 Apr 2020
    8.1
    High

    CVE-2020-5867

    Last Modified: 21 Nov 2024

    In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages

    Published: 23 Apr 2020
    9.8
    Critical

    CVE-2018-21133

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

    Published: 23 Apr 2020
    9.8
    Critical

    CVE-2018-21132

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

    Published: 23 Apr 2020
    9.1
    Critical

    CVE-2018-21131

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by unauthenticated firmware downgrade. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21110

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21109

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21108

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21107

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21106

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21105

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    5.5
    Medium

    CVE-2020-5866

    Last Modified: 21 Nov 2024

    In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.

    Published: 23 Apr 2020
    5.7
    Medium

    CVE-2019-17101

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions prior to x.xx of Netatmo Smart Indoor Camera allows an attacker to execute commands on the device. This issue affects: Netatmo Smart Indoor Camera version and prior versions.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21104

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    7.4
    High

    CVE-2020-5864

    Last Modified: 21 Nov 2024

    In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

    Published: 23 Apr 2020
    6.8
    Medium

    CVE-2018-21103

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2018-21102

    Last Modified: 21 Nov 2024

    NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

    Published: 23 Apr 2020
    4.8
    Medium

    CVE-2020-5865

    Last Modified: 21 Nov 2024

    In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.

    Published: 23 Apr 2020
    8
    High

    CVE-2018-21101

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

    Published: 23 Apr 2020
    5.5
    Medium

    CVE-2020-8798

    Last Modified: 21 Nov 2024

    httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.

    Published: 23 Apr 2020
    6.7
    Medium

    CVE-2020-8797

    Last Modified: 21 Nov 2024

    Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin from the local network.

    Published: 23 Apr 2020
    7.5
    High

    CVE-2020-12112

    Last Modified: 21 Nov 2024

    BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.

    Published: 23 Apr 2020
    6.1
    Medium

    CVE-2020-12113

    Last Modified: 21 Nov 2024

    BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

    Published: 23 Apr 2020
    5.4
    Medium

    CVE-2020-7132

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE Onboard Administrator. * OA 4.95 (Linux and Windows).

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18732

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, PLW1000v2 before 1.0.0.14, and PLW1010v2 before 1.0.0.14.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18733

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects D6220 before 1.0.0.28, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.8, R6400 before 1.0.1.22, R6400v2 before 1.0.2.32, R7100LG before 1.0.0.32, R7300DST before 1.0.0.52, R8300 before 1.0.2.94, and R8500 before 1.0.2.100.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18734

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.

    Published: 23 Apr 2020
    5.9
    Medium

    CVE-2020-12105

    Last Modified: 21 Nov 2024

    OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18735

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, and R6900v2 before 1.2.0.4.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18736

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, and WNDR3700v5 before 1.1.0.48.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18737

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0.4, WNDR3700v5 before 1.1.0.48, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18738

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX6150v2 before 1.0.1.54, R6400 before 1.0.1.24, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R6900P before 1.2.0.22, R7100LG before 1.0.0.32, R7300DST before 1.0.0.54, R7900 before 1.0.1.18, R8000 before 1.0.3.48, R8300 before 1.0.2.106, R8500 before 1.0.2.106, R6100 before 1.0.1.16, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.58.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18739

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects R6220 before V1.1.0.50, R7800 before V1.0.2.36, WNDR3400v3 before 1.0.1.14, and WNDR3700v5 before V1.1.0.48.

    Published: 23 Apr 2020
    6.3
    Medium

    CVE-2017-18740

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.61, D6000 before 1.0.0.61, D6100 before 1.0.0.55, D7800 before 1.0.1.28, R6100 before 1.0.1.16, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.40, WNDR3700v4 before 1.0.2.88, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.58.

    Published: 23 Apr 2020
    6.5
    Medium

    CVE-2017-18741

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6250 before 1.0.4.8, R6300v2 before 1.0.4.8, R6700 before 1.0.1.20, R7000 before 1.0.7.10, R7000P before 1.0.0.58, R6900P before 1.0.0.58, R7100LG before 1.0.0.32, R7900 before 1.0.1.14, R8000 before 1.0.3.22, and R8500 before 1.0.2.94.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18742

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by CSRF. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6250 before 1.0.4.12, R6300v2 before 1.0.4.8, R6700 before 1.0.1.16, R6900 before 1.0.1.16, R7300DST before 1.0.0.54, R7900 before 1.0.1.12, R8000 before 1.0.3.32, and R8500 before 1.0.2.74.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18743

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before 1.0.1.20, R6900 before 1.0.1.20, R7000 before 1.0.7.10, R7100LG before V1.0.0.32, R7300DST before 1.0.0.52, R7900 before 1.0.1.16, R8000 before 1.0.3.36, R8300 before 1.0.2.94, R8500 before 1.0.2.94, WNDR3400v3 before 1.0.1.12, and WNR3500Lv2 before 1.2.0.40.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18744

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects R6250 before 1.0.4.12, R6300v2 before 1.0.4.12, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000 before 1.0.9.4, R7900 before 1.0.1.12, R8000 before 1.0.3.24, and R8500 before 1.0.2.74.

    Published: 23 Apr 2020
    6.1
    Medium

    CVE-2017-18745

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects R6400 before 1.0.1.14, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000 before 1.0.9.4, R7100LG before 1.0.0.32, R7300DST before 1.0.0.56, R7900 before 1.0.1.12, R8000 before 1.0.3.24, and R8500 before 1.0.2.74.

    Published: 23 Apr 2020
    6.5
    Medium

    CVE-2017-18746

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6000 before 1.0.0.24, EX6130 before 1.0.0.16, EX6400 before 1.0.1.60, EX7000 before 1.0.0.50, EX7300 before 1.0.1.60, and WN2500RPv2 before 1.0.1.46.

    Published: 23 Apr 2020
    6.5
    Medium

    CVE-2017-18747

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6000 before 1.0.0.24, EX6130 before 1.0.0.16, EX6400 before 1.0.1.60, EX7000 before 1.0.0.50, EX7300 before 1.0.1.60, and WN2500RPv2 before 1.0.1.46.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18748

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects EX6200v2 before 1.0.1.44, R6100 before 1.0.1.12, R7500 before 1.0.0.108, R7500v2 before 1.0.3.10, R7800 before 1.0.2.28, R9000 before 1.0.2.30, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18749

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 before 1.0.1.10, R6100 before 1.0.1.16, R6220 before 1.1.0.50, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.40, WNDR3700v4 before 1.0.2.88, WNDR3700v5 before 1.1.0.48, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, WNR1000v4 before 1.1.0.44, WNR2000v5 before 1.0.0.58, WNR2020 before 1.1.0.44, and WNR2050 before 1.1.0.44.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18750

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2017-18751

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.16, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.88, WNDR4300 before 1.0.2.90, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

    Published: 23 Apr 2020
    7.5
    High

    CVE-2020-11940

    Last Modified: 21 Nov 2024

    In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's library.

    Published: 23 Apr 2020