📦 Xr500 Firmware

by Netgear

🔍 What is Xr500 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-38516

CRITICAL CVSS 10.0 Aug 11, 2021

This CVE describes a missing function-level access control vulnerability in numerous NETGEAR routers, gateways, and WiFi systems. It allows attackers to bypass authentication and access administrative...

CVE-2020-35795

CRITICAL CVSS 9.8 Dec 30, 2020

This CVE describes a critical buffer overflow vulnerability in multiple NETGEAR routers, range extenders, and Orbi WiFi systems. An unauthenticated attacker can exploit this remotely to execute arbitr...

CVE-2020-35800

CRITICAL CVSS 9.4 Dec 30, 2020

CVE-2020-35800 is a security misconfiguration vulnerability affecting numerous NETGEAR routers, range extenders, and Orbi WiFi systems. It allows attackers to bypass authentication and access administ...

CVE-2021-34947

HIGH CVSS 8.8 May 7, 2024

This is a critical remote code execution vulnerability in NETGEAR R7800 routers that allows network-adjacent attackers to execute arbitrary code as root without authentication. The vulnerability exist...

CVE-2021-45658

HIGH CVSS 7.1 Dec 26, 2021

This CVE describes a server-side injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Attackers can inject malicious code that executes on affected devices, potenti...

CVE-2021-45642

HIGH CVSS 7.5 Dec 26, 2021

This CVE affects multiple NETGEAR routers, extenders, and WiFi systems due to incorrect security configuration settings. The vulnerability could allow attackers to bypass security controls or gain una...

CVE-2021-45623

HIGH CVSS 8.3 Dec 26, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers via command injection. It affects R7800, R9000, and XR500 models running outdated firmware...

CVE-2021-38527

HIGH CVSS 8.1 Aug 11, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multiple NETGEAR routers, extenders, and WiFi systems ru...

CVE-2021-27251

HIGH CVSS 8.8 Apr 14, 2021

This vulnerability allows network-adjacent attackers to execute arbitrary code with root privileges on NETGEAR Nighthawk R7800 routers by exploiting insecure firmware update protocols. No authenticati...

CVE-2021-27253

HIGH CVSS 8.8 Apr 14, 2021

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code with root privileges on NETGEAR Nighthawk R7800 routers. The flaw exists in the handling of the...

CVE-2021-29069

HIGH CVSS 7.3 Mar 23, 2021

This vulnerability allows authenticated users on certain NETGEAR routers to execute arbitrary commands through command injection. It affects XR450, XR500, and WNR2000v5 routers running vulnerable firm...

CVE-2021-27255

HIGH CVSS 8.8 Mar 5, 2021

This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on NETGEAR R7800 routers. The flaw exists in the refresh_status.aspx endpoint which doesn't re...