📦 R7000p Firmware

by Netgear

🔍 What is R7000p Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36187

CRITICAL CVSS 9.8 Sep 1, 2023

A buffer overflow vulnerability in NETGEAR R6400v2 routers allows remote unauthenticated attackers to execute arbitrary code by sending a specially crafted URL to the httpd service. This affects all R...

CVE-2022-48322

CRITICAL CVSS 9.8 Feb 13, 2023

A pre-authentication stack-based buffer overflow vulnerability in NETGEAR Nighthawk WiFi Mesh systems and routers allows remote attackers to execute arbitrary code without authentication. This affects...

CVE-2021-45650

CRITICAL CVSS 9.1 Dec 26, 2021

This vulnerability in certain NETGEAR routers allows unauthorized disclosure of sensitive information. Attackers can potentially access confidential data stored on affected devices. Users with specifi...

CVE-2021-45638

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes a critical stack-based buffer overflow vulnerability in multiple NETGEAR router models that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability affe...

CVE-2021-45609

CRITICAL CVSS 9.6 Dec 26, 2021

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected NETGEAR routers via a buffer overflow. It affects multiple NETGEAR router models running outdated firmw...

CVE-2021-45617

CRITICAL CVSS 9.8 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multiple NETGEAR routers, extenders, and WiFi systems ru...

CVE-2021-45624

CRITICAL CVSS 9.6 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers via command injection. It affects multiple NETGEAR router models running vulnerable firmwa...

CVE-2021-45621

CRITICAL CVSS 9.6 Dec 26, 2021

CVE-2021-45621 is a critical command injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Unauthenticated attackers can execute arbitrary commands on affected devic...

CVE-2021-45527

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes a post-authentication buffer overflow vulnerability in multiple NETGEAR routers, extenders, and WiFi systems. An authenticated attacker could exploit this to execute arbitrary code ...

CVE-2021-45500

CRITICAL CVSS 9.6 Dec 26, 2021

This vulnerability allows attackers to bypass authentication on certain NETGEAR routers, potentially gaining unauthorized access to the device's administrative interface. It affects NETGEAR R7000P rou...

CVE-2021-38528

CRITICAL CVSS 9.6 Aug 11, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multiple NETGEAR router and gateway models running vulne...

CVE-2021-38516

CRITICAL CVSS 10.0 Aug 11, 2021

This CVE describes a missing function-level access control vulnerability in numerous NETGEAR routers, gateways, and WiFi systems. It allows attackers to bypass authentication and access administrative...

CVE-2020-35795

CRITICAL CVSS 9.8 Dec 30, 2020

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated attacker can exploit this remotely to execute arbitr...

CVE-2020-35800

CRITICAL CVSS 9.4 Dec 30, 2020

CVE-2020-35800 is a security misconfiguration vulnerability affecting numerous NETGEAR routers, range extenders, and Orbi WiFi systems. It allows attackers to bypass authentication and access administ...

CVE-2025-12945

HIGH CVSS 7.2 Dec 9, 2025

This vulnerability allows authenticated administrators on NETGEAR Nighthawk R7000P routers to execute arbitrary operating system commands through command injection. Attackers with admin credentials ca...

CVE-2024-12988

HIGH CVSS 7.3 Dec 27, 2024

A critical buffer overflow vulnerability in Netgear R6900P and R7000P routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP headers. This affects devices running ...

CVE-2024-52022

HIGH CVSS 8.0 Nov 5, 2024

This CVE describes a command injection vulnerability in specific Netgear router models via the wlg_adv.cgi component's apmode_gateway parameter. Attackers can execute arbitrary operating system comman...

CVE-2024-51021

HIGH CVSS 8.0 Nov 5, 2024

This CVE describes a command injection vulnerability in specific Netgear router models that allows attackers to execute arbitrary operating system commands via the wan_gateway parameter. Attackers can...

CVE-2024-51010

HIGH CVSS 8.0 Nov 5, 2024

This CVE describes a command injection vulnerability in specific Netgear router models that allows attackers to execute arbitrary operating system commands through the ap_mode.cgi component. Attackers...

CVE-2021-34982

HIGH CVSS 8.8 May 7, 2024

This is a critical stack-based buffer overflow vulnerability in NETGEAR routers' httpd service that allows network-adjacent attackers to execute arbitrary code as root without authentication. It affec...

CVE-2022-27642

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication on NETGEAR R6700v3 routers by exploiting incorrect string matching logic in the httpd service. Attackers can combine this ...

CVE-2022-27644

HIGH CVSS 8.8 Mar 29, 2023

CVE-2022-27644 is a certificate validation vulnerability in NETGEAR R6700v3 routers that allows network-adjacent attackers to intercept HTTPS downloads. This can lead to arbitrary code execution as ro...

CVE-2022-27646

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR R6700v3 routers by exploiting a stack-based buffer overflow in ...

CVE-2021-45649

HIGH CVSS 7.9 Dec 26, 2021

This vulnerability in certain NETGEAR routers allows unauthorized disclosure of sensitive information. Attackers can potentially access confidential data stored on affected devices. Users of specific ...

CVE-2021-45553

HIGH CVSS 8.7 Dec 26, 2021

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers. It affects R7000, R6900P, and R7000P models running outdated firmware versions. Attackers m...

CVE-2021-45549

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers, extenders, and WiFi systems. Attackers with valid credentials can inject malicious commands thr...

CVE-2021-45526

HIGH CVSS 7.3 Dec 26, 2021

This vulnerability allows an authenticated attacker to trigger a buffer overflow on affected NETGEAR routers and extenders. Successful exploitation could lead to arbitrary code execution or device com...

CVE-2021-45529

HIGH CVSS 7.3 Dec 26, 2021

This vulnerability allows an authenticated attacker to trigger a buffer overflow on affected NETGEAR routers. Successful exploitation could lead to remote code execution or denial of service. Only use...

CVE-2021-45512

HIGH CVSS 8.6 Dec 26, 2021

This vulnerability affects multiple NETGEAR routers and extenders that use weak cryptography implementations, potentially allowing attackers to decrypt sensitive communications or bypass authenticatio...

CVE-2021-45499

HIGH CVSS 8.2 Dec 26, 2021

This vulnerability allows attackers to bypass authentication on affected NETGEAR routers, potentially gaining unauthorized access to administrative interfaces. It affects specific NETGEAR router model...

CVE-2021-34991

HIGH CVSS 8.8 Nov 15, 2021

This is a critical buffer overflow vulnerability in NETGEAR R6400v2 routers that allows network-adjacent attackers to execute arbitrary code as root without authentication. The flaw exists in the UPnP...

CVE-2021-40847

HIGH CVSS 8.1 Sep 21, 2021

This vulnerability allows remote attackers to execute arbitrary code as root on affected NETGEAR routers via a man-in-the-middle attack. The Circle update daemon downloads unsigned updates over HTTP, ...

CVE-2021-27239

HIGH CVSS 8.8 Mar 29, 2021

This vulnerability allows attackers on the same network to execute arbitrary code as root on NETGEAR R6400 and R6700 routers without authentication. The flaw exists in the upnpd service, where a craft...

CVE-2021-29080

HIGH CVSS 8.1 Mar 23, 2021

This vulnerability allows unauthenticated attackers to reset passwords on affected NETGEAR routers and WiFi systems. Attackers can gain administrative access without credentials, compromising network ...

CVE-2024-52024

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability allows attackers to cause a Denial of Service (DoS) on affected Netgear routers by sending a specially crafted POST request that triggers a stack overflow in the pppoe_localip param...

CVE-2024-52026

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability allows attackers to cause a Denial of Service (DoS) on affected Netgear routers by sending a specially crafted POST request that triggers a stack overflow in the pppoe_localip param...

CVE-2024-52029

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability in Netgear R7000P routers allows attackers to trigger a stack overflow via the pptp_user_netmask parameter in the genie_pptp.cgi script. Attackers can cause a Denial of Service (DoS...

CVE-2024-52013

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability is a stack overflow in Netgear routers' pptp_user_ip parameter at wiz_pptp.cgi. Attackers can exploit it via crafted POST requests to cause Denial of Service (DoS), potentially cras...

CVE-2024-52015

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability is a stack overflow in specific Netgear router models via the pptp_user_ip parameter in the bsw_pptp.cgi script. Attackers can exploit it by sending a crafted POST request to cause ...

CVE-2024-51018

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability in Netgear R7000P routers allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the pptp.cgi endpoint. The stack overflow in the pptp_us...

CVE-2024-51020

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability in Netgear R7000P routers allows attackers to trigger a stack overflow via the apn parameter in usbISP_detail_edit.cgi, leading to Denial of Service (DoS). Attackers can exploit thi...

CVE-2024-51003

MEDIUM CVSS 5.7 Nov 5, 2024

Multiple Netgear router models contain stack overflow vulnerabilities in the ap_mode.cgi component via DNS parameters. Attackers can exploit these vulnerabilities by sending crafted POST requests to c...

CVE-2024-50997

MEDIUM CVSS 5.7 Nov 5, 2024

This vulnerability allows attackers to cause a Denial of Service (DoS) on affected Netgear routers by sending a specially crafted POST request to the pptp.cgi endpoint. The stack overflow in the pptp_...