Page 14 of 68 results (0.003 seconds)

CVSS: 7.2EPSS: 0%CPEs: 22EXPL: 0

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.60, D3600 before 1.0.0.75, D6000 before 1.0.0.75, R9000 before 1.0.4.26, R8900 before 1.0.4.26, R7800 before 1.0.2.52, WNDR4500v3 before 1.0.0.58, WNDR4300v2 before 1.0.0.58, WNDR4300 before 1.0.2.104, WNDR3700v4 before 1.0.2.102, and WNR2000v5 before 1.0.0.66. Determinados dispositivos NETGEAR están afectados por un desbordamiento del búfer en la región stack de la memoria por parte de un usuario autenticado. Esto afecta a D6100 versiones anteriores a 1.0.0.60, D3600 versiones anteriores a 1.0.0.75, D6000 versiones anteriores a 1.0.0.75, R9000 versiones anteriores a 1.0.4.26, R8900 versiones anteriores a 1.0.4.26, R7800 versiones anteriores a 1.0.2.52, WNDR4500v3 versiones anteriores a 1.0.0.58, WNDR4300v2 versiones anteriores a 1.0.0.58, WNDR4300 versiones anteriores a 1.0.2.104, WNDR3700v4 versiones anteriores a 1.0.2.102 y WNR2000v5 versiones anteriores a 1.0.0.66. • https://kb.netgear.com/000060632/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-Some-Routers-and-Modem-Routers-PSV-2018-0116 • CWE-787: Out-of-bounds Write •

CVSS: 5.9EPSS: 0%CPEs: 4EXPL: 0

NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation. Dispositivos NETGEAR D3600 con firmware 1.0.0.49 y dispositivos D6000 con firmware 1.0.0.49 y versiones anteriores utilizan la misma clave privada embebida en instalaciones de clientes diferentes, lo que permite a a atacantes remotos vencer mecanismos de protección criptográficos aprovechando el conocimiento de esta clave de otra instalación. • http://kb.netgear.com/app/answers/detail/a_id/30560 http://www.kb.cert.org/vuls/id/778696 •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp HTML source code. La característica de recuperación de contraseña en dispositivos NETGEAR D3600 con firmware 1.0.0.49 y dispositivos D6000 con firmware 1.0.0.49 y versiones anteriores permite a atacantes remotos descubrir la contraseña del administrador en texto plano leyendo el código fuente HTML cgi-bin/passrec.asp. • http://kb.netgear.com/app/answers/detail/a_id/30490 http://www.kb.cert.org/vuls/id/778696 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-255: Credentials Management Errors •