📦 R6700 Firmware

by Netgear

🔍 What is R6700 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-30280

CRITICAL CVSS 9.8 Apr 26, 2023

A buffer overflow vulnerability in Netgear R6900, R6700v3, and R6700 routers allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the f...

CVE-2021-38516

CRITICAL CVSS 10.0 Aug 11, 2021

This CVE describes a missing function-level access control vulnerability in numerous NETGEAR routers, gateways, and WiFi systems. It allows attackers to bypass authentication and access administrative...

CVE-2020-35795

CRITICAL CVSS 9.8 Dec 30, 2020

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated attacker can exploit this remotely to execute arbitr...

CVE-2022-27642

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication on NETGEAR R6700v3 routers by exploiting incorrect string matching logic in the httpd service. Attackers can combine this ...

CVE-2022-27644

HIGH CVSS 8.8 Mar 29, 2023

CVE-2022-27644 is a certificate validation vulnerability in NETGEAR R6700v3 routers that allows network-adjacent attackers to intercept HTTPS downloads. This can lead to arbitrary code execution as ro...

CVE-2022-27646

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR R6700v3 routers by exploiting a stack-based buffer overflow in ...

CVE-2021-45732

HIGH CVSS 8.8 Dec 30, 2021

CVE-2021-45732 is a hardcoded credential vulnerability in Netgear Nighthawk R6700 routers that allows attackers to decrypt configuration backups, modify restricted settings, and restore malicious conf...

CVE-2021-20174

HIGH CVSS 7.5 Dec 30, 2021

This vulnerability exposes Netgear Nighthawk R6700 router credentials to interception by using unencrypted HTTP instead of HTTPS for web interface communication. Attackers on the same network can capt...

CVE-2021-45656

HIGH CVSS 7.1 Dec 26, 2021

This CVE describes a server-side injection vulnerability in multiple NETGEAR router and WiFi system models, allowing attackers to execute arbitrary code or commands on affected devices. It impacts use...

CVE-2021-45573

HIGH CVSS 8.3 Dec 26, 2021

This CVE describes a stack-based buffer overflow vulnerability in multiple NETGEAR router models that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability affects speci...

CVE-2021-45549

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers, extenders, and WiFi systems. Attackers with valid credentials can inject malicious commands thr...

CVE-2021-45512

HIGH CVSS 8.6 Dec 26, 2021

This vulnerability affects multiple NETGEAR routers and extenders that use weak cryptography implementations, potentially allowing attackers to decrypt sensitive communications or bypass authenticatio...

CVE-2021-40847

HIGH CVSS 8.1 Sep 21, 2021

This vulnerability allows remote attackers to execute arbitrary code as root on affected NETGEAR routers via a man-in-the-middle attack. The Circle update daemon downloads unsigned updates over HTTP, ...

CVE-2021-38515

HIGH CVSS 7.4 Aug 11, 2021

This vulnerability affects specific NETGEAR router models, allowing attackers to cause denial of service by crashing the device. Affected users include those running vulnerable firmware versions on R6...

CVE-2021-27239

HIGH CVSS 8.8 Mar 29, 2021

This vulnerability allows attackers on the same network to execute arbitrary code as root on NETGEAR R6400 and R6700 routers without authentication. The flaw exists in the upnpd service, where a craft...

CVE-2020-27872

HIGH CVSS 8.8 Feb 4, 2021

This vulnerability allows network-adjacent attackers to bypass authentication on NETGEAR R7450 routers by exploiting improper state tracking in the password recovery process. Attackers can leverage th...