📦 Rax80 Firmware

by Netgear

🔍 What is Rax80 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36187

CRITICAL CVSS 9.8 Sep 1, 2023

A buffer overflow vulnerability in NETGEAR R6400v2 routers allows remote unauthenticated attackers to execute arbitrary code by sending a specially crafted URL to the httpd service. This affects all R...

CVE-2021-45611

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR router models that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability affects specific...

CVE-2021-45613

CRITICAL CVSS 9.6 Dec 26, 2021

CVE-2021-45613 is a critical command injection vulnerability affecting multiple NETGEAR routers and WiFi systems. Unauthenticated attackers can execute arbitrary commands on affected devices, potentia...

CVE-2021-45617

CRITICAL CVSS 9.8 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multiple NETGEAR routers, extenders, and WiFi systems ru...

CVE-2021-45621

CRITICAL CVSS 9.6 Dec 26, 2021

CVE-2021-45621 is a critical command injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Unauthenticated attackers can execute arbitrary commands on affected devic...

CVE-2021-45527

CRITICAL CVSS 9.6 Dec 26, 2021

This CVE describes a post-authentication buffer overflow vulnerability in multiple NETGEAR routers, extenders, and WiFi systems. An authenticated attacker could exploit this to execute arbitrary code ...

CVE-2020-35795

CRITICAL CVSS 9.8 Dec 30, 2020

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated attacker can exploit this remotely to execute arbitr...

CVE-2020-35800

CRITICAL CVSS 9.4 Dec 30, 2020

CVE-2020-35800 is a security misconfiguration vulnerability affecting numerous NETGEAR routers, range extenders, and Orbi WiFi systems. It allows attackers to bypass authentication and access administ...

CVE-2021-34982

HIGH CVSS 8.8 May 7, 2024

This is a critical stack-based buffer overflow vulnerability in NETGEAR routers' httpd service that allows network-adjacent attackers to execute arbitrary code as root without authentication. It affec...

CVE-2022-27642

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication on NETGEAR R6700v3 routers by exploiting incorrect string matching logic in the httpd service. Attackers can combine this ...

CVE-2022-27644

HIGH CVSS 8.8 Mar 29, 2023

CVE-2022-27644 is a certificate validation vulnerability in NETGEAR R6700v3 routers that allows network-adjacent attackers to intercept HTTPS downloads. This can lead to arbitrary code execution as ro...

CVE-2022-27646

HIGH CVSS 8.8 Mar 29, 2023

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR R6700v3 routers by exploiting a stack-based buffer overflow in ...

CVE-2021-45545

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. Attackers with valid credentials can gain elevated p...

CVE-2021-45547

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. It affects multiple NETGEAR router models running ou...

CVE-2021-45549

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers, extenders, and WiFi systems. Attackers with valid credentials can inject malicious commands thr...

CVE-2021-45526

HIGH CVSS 7.3 Dec 26, 2021

This vulnerability allows an authenticated attacker to trigger a buffer overflow on affected NETGEAR routers and extenders. Successful exploitation could lead to arbitrary code execution or device com...

CVE-2021-45535

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users on certain NETGEAR routers and WiFi systems to execute arbitrary commands through command injection. It affects multiple NETGEAR models including RAX200, ...

CVE-2021-45537

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects multiple NETGEAR models including RAX200, RAX75, RAX80, RBK752,...

CVE-2021-45539

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects multiple NETGEAR device models running vulnerable firmware vers...

CVE-2021-45541

HIGH CVSS 8.4 Dec 26, 2021

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. Attackers with valid credentials can gain elevated p...

CVE-2021-45499

HIGH CVSS 8.2 Dec 26, 2021

This vulnerability allows attackers to bypass authentication on affected NETGEAR routers, potentially gaining unauthorized access to administrative interfaces. It affects specific NETGEAR router model...

CVE-2021-34991

HIGH CVSS 8.8 Nov 15, 2021

This is a critical buffer overflow vulnerability in NETGEAR R6400v2 routers that allows network-adjacent attackers to execute arbitrary code as root without authentication. The flaw exists in the UPnP...

CVE-2021-38518

HIGH CVSS 8.4 Aug 11, 2021

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects specific NETGEAR models running outdated firmware versions. Att...

CVE-2021-27239

HIGH CVSS 8.8 Mar 29, 2021

This vulnerability allows attackers on the same network to execute arbitrary code as root on NETGEAR R6400 and R6700 routers without authentication. The flaw exists in the upnpd service, where a craft...

CVE-2021-29080

HIGH CVSS 8.1 Mar 23, 2021

This vulnerability allows unauthenticated attackers to reset passwords on affected NETGEAR routers and WiFi systems. Attackers can gain administrative access without credentials, compromising network ...

CVE-2021-29073

HIGH CVSS 7.6 Mar 23, 2021

This CVE describes a stack-based buffer overflow vulnerability in certain NETGEAR routers and WiFi systems that allows an authenticated attacker to execute arbitrary code. The vulnerability affects mu...