D6400 Firmware
NETGEAR · 52 CVEs
Netgear D6400 diag.cgi os command injection
Jul 10, 2025
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability
May 7, 2024
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability
May 7, 2024
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R67…
Mar 29, 2023
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.68,…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,…
Dec 26, 2021
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 bef…
Dec 26, 2021
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0…
Dec 26, 2021
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D622…
Dec 26, 2021
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.7…
Dec 26, 2021
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.7…
Dec 26, 2021
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R64…
Nov 15, 2021
Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.4…
Aug 11, 2021
Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6100 be…
Aug 10, 2021
Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.7…
Aug 10, 2021
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R64…
Mar 29, 2021
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 29, 2020
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.…
Dec 29, 2020
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.38,…
Apr 27, 2020
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.2…
Apr 24, 2020
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.2…
Apr 24, 2020
Certain NETGEAR devices are affected by stored XSS. This affects D6400 before 1.0.0.60, D7000 before 1.0.1.50, D8500 be…
Apr 24, 2020
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.…
Apr 24, 2020
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0…
Apr 23, 2020
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 b…
Apr 23, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-7407 | Netgear D6400 diag.cgi os command injection | MEDIUM | 10.45% | Jul 10, 2025 |
| CVE-2021-34983 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability | MEDIUM | 0.33% | May 7, 2024 |
| CVE-2021-34982 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability | HIGH | 0.58% | May 7, 2024 |
| CVE-2022-27643 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authenti… | HIGH | 25.44% | Mar 29, 2023 |
| CVE-2021-45527 | Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.68, D6400 before 1.0.0.102, D7000v2 before… | CRITICAL | 1.13% | Dec 26, 2021 |
| CVE-2021-45550 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.78, D6100 before 1.0… | MEDIUM | 0.57% | Dec 26, 2021 |
| CVE-2021-45604 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D64… | MEDIUM | 0.37% | Dec 26, 2021 |
| CVE-2021-45610 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.66, D6400 before 1.0.0.100, D7000v2 b… | CRITICAL | 1.44% | Dec 26, 2021 |
| CVE-2021-45638 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6220 before 1.0.0.68, D6400 before 1.0.0.10… | CRITICAL | 1.47% | Dec 26, 2021 |
| CVE-2021-45640 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1… | HIGH | 0.62% | Dec 26, 2021 |
| CVE-2021-45641 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1… | HIGH | 0.69% | Dec 26, 2021 |
| CVE-2021-34991 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authenti… | HIGH | 5.67% | Nov 15, 2021 |
| CVE-2021-38516 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before… | CRITICAL | 1.34% | Aug 11, 2021 |
| CVE-2021-38534 | Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6100 before 1.0.0.60, D6200 before 1.1.00.36, D… | MEDIUM | 0.51% | Aug 10, 2021 |
| CVE-2021-38514 | Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1… | LOW | 0.77% | Aug 10, 2021 |
| CVE-2021-27239 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400 and R6700 firmware version 1.0.4.98 r… | HIGH | 0.74% | Mar 29, 2021 |
| CVE-2020-35796 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D6220 before 1.0.0.60, D6400 befo… | CRITICAL | 1.30% | Dec 29, 2020 |
| CVE-2020-35800 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 befor… | CRITICAL | 1.61% | Dec 29, 2020 |
| CVE-2018-21156 | Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.38, D6400 before 1.0.0.74, D7000v2 before 1… | HIGH | 1.35% | Apr 27, 2020 |
| CVE-2018-21230 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.… | MEDIUM | 0.47% | Apr 24, 2020 |
| CVE-2018-21231 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.… | MEDIUM | 0.47% | Apr 24, 2020 |
| CVE-2017-18700 | Certain NETGEAR devices are affected by stored XSS. This affects D6400 before 1.0.0.60, D7000 before 1.0.1.50, D8500 before 1.0.3.29, EX6200 before 1.0.3.84, E… | MEDIUM | 0.65% | Apr 24, 2020 |
| CVE-2017-18704 | Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.32, D6400 before 1.0.0.60, D8500 before… | MEDIUM | 0.49% | Apr 24, 2020 |
| CVE-2018-21162 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86, EX7000 be… | CRITICAL | 3.44% | Apr 23, 2020 |
| CVE-2018-21139 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.58, D… | HIGH | 1.19% | Apr 23, 2020 |
Showing 1 to 25 of 52 CVEs