📦 Cbr40 Firmware

by Netgear

🔍 What is Cbr40 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36187

CRITICAL CVSS 9.8 Sep 1, 2023

A buffer overflow vulnerability in NETGEAR R6400v2 routers allows remote unauthenticated attackers to execute arbitrary code by sending a specially crafted URL to the httpd service. This affects all R...

CVE-2021-45628

CRITICAL CVSS 9.6 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects multiple NETGEAR router and mesh WiFi system mo...

CVE-2021-45630

CRITICAL CVSS 10.0 Dec 26, 2021

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple NETGEAR Orbi and Nighthawk models running outdated firmwa...

CVE-2021-45613

CRITICAL CVSS 9.6 Dec 26, 2021

CVE-2021-45613 is a critical command injection vulnerability affecting multiple NETGEAR routers and WiFi systems. Unauthenticated attackers can execute arbitrary commands on affected devices, potentia...

CVE-2021-45615

CRITICAL CVSS 9.6 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. It affects multiple NETGEAR models with specif...

CVE-2021-45617

CRITICAL CVSS 9.8 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multiple NETGEAR routers, extenders, and WiFi systems ru...

CVE-2021-45621

CRITICAL CVSS 9.6 Dec 26, 2021

CVE-2021-45621 is a critical command injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Unauthenticated attackers can execute arbitrary commands on affected devic...

CVE-2021-45504

CRITICAL CVSS 9.6 Dec 26, 2021

This vulnerability allows attackers to bypass authentication on certain NETGEAR WiFi systems, potentially gaining unauthorized access to device administration interfaces. Affected devices include spec...

CVE-2021-45508

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes an authentication bypass vulnerability in specific NETGEAR WiFi systems. Attackers can potentially gain unauthorized access to device administration interfaces without valid credent...

CVE-2020-35795

CRITICAL CVSS 9.8 Dec 30, 2020

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated attacker can exploit this remotely to execute arbitr...

CVE-2020-35800

CRITICAL CVSS 9.4 Dec 30, 2020

CVE-2020-35800 is a security misconfiguration vulnerability affecting numerous NETGEAR routers, range extenders, and Orbi WiFi systems. It allows attackers to bypass authentication and access administ...

CVE-2020-26926

CRITICAL CVSS 9.6 Oct 9, 2020

This vulnerability allows attackers to bypass authentication on affected NETGEAR WiFi systems, potentially gaining unauthorized access to network administration interfaces. It affects specific NETGEAR...

CVE-2020-26928

CRITICAL CVSS 9.6 Oct 9, 2020

This CVE describes an authentication bypass vulnerability affecting specific NETGEAR WiFi systems. Attackers can bypass authentication mechanisms to gain unauthorized access to device administration i...

CVE-2020-26905

CRITICAL CVSS 9.6 Oct 9, 2020

This vulnerability allows attackers to obtain administrative credentials on certain NETGEAR WiFi systems, potentially leading to full device compromise. It affects specific NETGEAR CBR40, RBK752, RBR7...

CVE-2020-26903

CRITICAL CVSS 9.6 Oct 9, 2020

This vulnerability allows attackers to obtain administrative credentials on affected NETGEAR WiFi systems. Attackers can gain full administrative control over the devices, potentially compromising the...

CVE-2020-26899

CRITICAL CVSS 9.6 Oct 9, 2020

This vulnerability in certain NETGEAR WiFi systems allows unauthorized disclosure of sensitive information. Attackers can potentially access confidential data stored on affected devices. The vulnerabi...

CVE-2020-26897

CRITICAL CVSS 9.6 Oct 9, 2020

This vulnerability allows attackers to retrieve administrative credentials from affected NETGEAR WiFi systems. Attackers could gain full administrative control over the devices. Affected devices inclu...

CVE-2024-28340

HIGH CVSS 7.5 Mar 12, 2024

This vulnerability allows unauthenticated attackers to access sensitive information from Netgear CBR40, CBK40, and CBK43 routers via the currentsetting.htm component. The information leak exposes pote...

CVE-2022-27644

HIGH CVSS 8.8 Mar 29, 2023

CVE-2022-27644 is a certificate validation vulnerability in NETGEAR R6700v3 routers that allows network-adjacent attackers to intercept HTTPS downloads. This can lead to arbitrary code execution as ro...

CVE-2022-27646

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR R6700v3 routers by exploiting a stack-based buffer overflow in ...

CVE-2021-45597

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects specific NETGEAR CBR40, CBR750, RBR850, and RBS850 devices running vulnerable f...

CVE-2021-45599

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects specific NETGEAR CBR40, CBR750, RBK852, RBR850, and RBS850 devices running vuln...

CVE-2021-45601

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users on certain NETGEAR WiFi systems to execute arbitrary commands through command injection. It affects specific NETGEAR CBR40, CBR750, RBK852, RBR850, and RB...

CVE-2021-45529

HIGH CVSS 7.3 Dec 26, 2021

This vulnerability allows an authenticated attacker to trigger a buffer overflow on affected NETGEAR routers. Successful exploitation could lead to remote code execution or denial of service. Only use...

CVE-2021-38527

HIGH CVSS 8.1 Aug 11, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multiple NETGEAR routers, extenders, and WiFi systems ru...

CVE-2021-29080

HIGH CVSS 8.1 Mar 23, 2021

This vulnerability allows unauthenticated attackers to reset passwords on affected NETGEAR routers and WiFi systems. Attackers can gain administrative access without credentials, compromising network ...