NETGEAR XR300 FIRMWARE 1.0.3.78

CPE Details

NETGEAR XR300 FIRMWARE 1.0.3.78
1.0.3.78
2023-08-08
15h06 +00:00
2023-08-29
10h24 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:netgear:xr300_firmware:1.0.3.78:*:*:*:*:*:*:*

Informations

Vendor

netgear

Product

xr300_firmware

Version

1.0.3.78

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-50996 2024-11-04 23h00 +00:00 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-50997 2024-11-04 23h00 +00:00 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-51002 2024-11-04 23h00 +00:00 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-51003 2024-11-04 23h00 +00:00 Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-51007 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-51008 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
8
High
CVE-2024-51014 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid_an parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-51016 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-51022 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-52017 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
5.7
Medium
CVE-2024-52018 2024-11-04 23h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
8
High
CVE-2023-36499 2023-08-06 22h00 +00:00 Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi.
8.8
High