Ex6120 Firmware
NETGEAR · 44 CVEs
Certain NETGEAR devices allow administrators to tamper with system
Jun 9, 2026
Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router
Jun 9, 2026
Netgear EX6120 sub_30394 buffer overflow
Apr 30, 2025
Netgear EX6120 fwAcosCgiInbound buffer overflow
Apr 30, 2025
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in…
Oct 14, 2024
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
Oct 14, 2024
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability
May 7, 2024
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability
May 7, 2024
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R67…
Mar 29, 2023
Certain NETGEAR devices are affected by weak cryptography. This affects D7000v2 before 1.0.0.62, D8500 before 1.0.3.50,…
Dec 26, 2021
Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects EX6000 before 1.0.0.38…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 26, 2021
Certain NETGEAR devices are affected by reflected XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.32, EAX80…
Dec 26, 2021
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.7…
Dec 26, 2021
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.7…
Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX3700 b…
Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.64, EX3700 b…
Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 be…
Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 b…
Dec 26, 2021
Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 be…
Dec 26, 2021
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R64…
Nov 15, 2021
Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 befor…
Aug 10, 2021
Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.7…
Aug 10, 2021
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 29, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-0418 | Certain NETGEAR devices allow administrators to tamper with system | MEDIUM | 0.24% | Jun 9, 2026 |
| CVE-2026-9210 | Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router | MEDIUM | 0.35% | Jun 9, 2026 |
| CVE-2025-4140 | Netgear EX6120 sub_30394 buffer overflow | HIGH | 1.20% | Apr 30, 2025 |
| CVE-2025-4139 | Netgear EX6120 fwAcosCgiInbound buffer overflow | HIGH | 1.15% | Apr 30, 2025 |
| CVE-2024-35519 | Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode para… | HIGH | 1.04% | Oct 14, 2024 |
| CVE-2024-35518 | Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter. | HIGH | 1.05% | Oct 14, 2024 |
| CVE-2021-34983 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability | MEDIUM | 0.33% | May 7, 2024 |
| CVE-2021-34982 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability | HIGH | 0.58% | May 7, 2024 |
| CVE-2022-27643 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authenti… | HIGH | 25.44% | Mar 29, 2023 |
| CVE-2021-45512 | Certain NETGEAR devices are affected by weak cryptography. This affects D7000v2 before 1.0.0.62, D8500 before 1.0.3.50, EX3700 before 1.0.0.84, EX3800 before 1… | CRITICAL | 0.54% | Dec 26, 2021 |
| CVE-2021-45526 | Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects EX6000 before 1.0.0.38, EX6120 before 1.0.0.48, EX6130 before… | HIGH | 0.45% | Dec 26, 2021 |
| CVE-2021-45533 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66, EX6130 before 1.0.0.46, EX7000 before… | HIGH | 0.63% | Dec 26, 2021 |
| CVE-2021-45621 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, EAX20 bef… | CRITICAL | 2.02% | Dec 26, 2021 |
| CVE-2021-45639 | Certain NETGEAR devices are affected by reflected XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.32, EAX80 before 1.0.1.62, EX6120 before 1.0.0.64… | MEDIUM | 0.60% | Dec 26, 2021 |
| CVE-2021-45640 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1… | HIGH | 0.62% | Dec 26, 2021 |
| CVE-2021-45641 | Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1… | HIGH | 0.69% | Dec 26, 2021 |
| CVE-2021-45665 | Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90,… | MEDIUM | 0.42% | Dec 26, 2021 |
| CVE-2021-45666 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90,… | MEDIUM | 0.42% | Dec 26, 2021 |
| CVE-2021-45667 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, E… | MEDIUM | 0.42% | Dec 26, 2021 |
| CVE-2021-45668 | Certain NETGEAR devices are affected by stored XSS. This affects EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX3700 before 1.0.0.90, EX3800 before 1.0.0.90,… | MEDIUM | 0.42% | Dec 26, 2021 |
| CVE-2021-45670 | Certain NETGEAR devices are affected by stored XSS. This affects CBR40 before 2.5.0.10, EAX20 before 1.0.0.48, EAX80 before 1.0.1.64, EX6120 before 1.0.0.64, E… | MEDIUM | 0.42% | Dec 26, 2021 |
| CVE-2021-34991 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authenti… | HIGH | 5.67% | Nov 15, 2021 |
| CVE-2021-32122 | Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44. | CRITICAL | 0.43% | Aug 10, 2021 |
| CVE-2021-38514 | Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1… | LOW | 0.77% | Aug 10, 2021 |
| CVE-2020-35796 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects CBR40 before 2.5.0.10, D6220 before 1.0.0.60, D6400 befo… | CRITICAL | 1.30% | Dec 29, 2020 |
Showing 1 to 25 of 44 CVEs