Mr60 Firmware
NETGEAR · 39 CVEs
Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.
Aug 11, 2026
Command injection vulnerability in some NETGEAR Nighthawk devices
Aug 11, 2026
Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
Aug 11, 2026
Certain NETGEAR devices allow administrators to tamper with system
Jun 9, 2026
Insufficient input validation in certain NETGEAR routers
Jun 9, 2026
Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router
Jun 9, 2026
NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability
May 7, 2024
NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability
May 7, 2024
Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to e…
Sep 1, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R67…
Mar 29, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R670…
Mar 29, 2023
NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affec…
Feb 13, 2023
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.9…
Jan 30, 2023
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.12…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38,…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28,…
Dec 26, 2021
Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 bef…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 26, 2021
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5…
Dec 26, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-11738 | Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device. | MEDIUM | 0.27% | Aug 11, 2026 |
| CVE-2026-11739 | Command injection vulnerability in some NETGEAR Nighthawk devices | MEDIUM | 1.07% | Aug 11, 2026 |
| CVE-2026-11814 | Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers | MEDIUM | 0.91% | Aug 11, 2026 |
| CVE-2026-0418 | Certain NETGEAR devices allow administrators to tamper with system | MEDIUM | 0.24% | Jun 9, 2026 |
| CVE-2026-0417 | Insufficient input validation in certain NETGEAR routers | MEDIUM | 0.23% | Jun 9, 2026 |
| CVE-2026-9210 | Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router | MEDIUM | 0.35% | Jun 9, 2026 |
| CVE-2021-34983 | NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability | MEDIUM | 0.33% | May 7, 2024 |
| CVE-2021-34982 | NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability | HIGH | 0.58% | May 7, 2024 |
| CVE-2023-36187 | Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to… | CRITICAL | 1.13% | Sep 1, 2023 |
| CVE-2022-27647 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although… | HIGH | 1.47% | Mar 29, 2023 |
| CVE-2022-27642 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentic… | HIGH | 0.88% | Mar 29, 2023 |
| CVE-2022-48322 | NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.… | CRITICAL | 0.68% | Feb 13, 2023 |
| CVE-2022-48176 | Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authe… | HIGH | 0.45% | Jan 30, 2023 |
| CVE-2021-45539 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1… | HIGH | 0.63% | Dec 26, 2021 |
| CVE-2021-45540 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R7900 before 1.0.4.46, R7900P before… | HIGH | 0.63% | Dec 26, 2021 |
| CVE-2021-45541 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38, R7900P before 1.4.2.84, R8000 before 1.… | HIGH | 1.48% | Dec 26, 2021 |
| CVE-2021-45549 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28, MK62 before 1.1.6.122, MR60 before 1.1.… | HIGH | 0.63% | Dec 26, 2021 |
| CVE-2021-45604 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects CBR750 before 3.2.18.2, D6220 before 1.0.0.68, D64… | MEDIUM | 0.37% | Dec 26, 2021 |
| CVE-2021-45612 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 befo… | CRITICAL | 2.49% | Dec 26, 2021 |
| CVE-2021-45613 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, D7000v2 be… | CRITICAL | 2.02% | Dec 26, 2021 |
| CVE-2021-45614 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.0.0.74, LAX20 before 1.1.6.28, MK62 bef… | CRITICAL | 2.02% | Dec 26, 2021 |
| CVE-2021-45616 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2.18.2, LAX20 before 1.1.6.28, MK62 befo… | CRITICAL | 2.02% | Dec 26, 2021 |
| CVE-2021-45617 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, EAX20 before 1.0.0.48, EAX80 befo… | CRITICAL | 2.06% | Dec 26, 2021 |
| CVE-2021-45620 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, EAX20 befo… | CRITICAL | 2.02% | Dec 26, 2021 |
| CVE-2021-45621 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.24, CBR750 before 3.2.18.2, EAX20 bef… | CRITICAL | 2.02% | Dec 26, 2021 |
Showing 1 to 25 of 39 CVEs