📦 D6400 Firmware

by Netgear

🔍 What is D6400 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-45638

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes a critical stack-based buffer overflow vulnerability in multiple NETGEAR router models that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability affe...

CVE-2021-45527

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes a post-authentication buffer overflow vulnerability in multiple NETGEAR routers, extenders, and WiFi systems. An authenticated attacker could exploit this to execute arbitrary code ...

CVE-2021-38516

CRITICAL CVSS 10.0 Aug 11, 2021

This CVE describes a missing function-level access control vulnerability in numerous NETGEAR routers, gateways, and WiFi systems. It allows attackers to bypass authentication and access administrative...

CVE-2020-35800

CRITICAL CVSS 9.4 Dec 30, 2020

CVE-2020-35800 is a security misconfiguration vulnerability affecting numerous NETGEAR routers, range extenders, and Orbi WiFi systems. It allows attackers to bypass authentication and access administ...

CVE-2021-34982

HIGH CVSS 8.8 May 7, 2024

This is a critical stack-based buffer overflow vulnerability in NETGEAR routers' httpd service that allows network-adjacent attackers to execute arbitrary code as root without authentication. It affec...

CVE-2021-34991

HIGH CVSS 8.8 Nov 15, 2021

This is a critical buffer overflow vulnerability in NETGEAR R6400v2 routers that allows network-adjacent attackers to execute arbitrary code as root without authentication. The flaw exists in the UPnP...

CVE-2021-27239

HIGH CVSS 8.8 Mar 29, 2021

This vulnerability allows attackers on the same network to execute arbitrary code as root on NETGEAR R6400 and R6700 routers without authentication. The flaw exists in the upnpd service, where a craft...

CVE-2025-7407

MEDIUM CVSS 6.3 Jul 10, 2025

This critical vulnerability in Netgear D6400 routers allows remote attackers to execute arbitrary operating system commands via command injection in the diag.cgi file's host_name parameter. It affects...