Known vulnerabilities in XR1000

Vendor: NETGEAR
Software: XR1000
Software CPE: cpe:2.3:h:netgear:xr1000:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting XR1000 XR1000 is affected by 23 known vulnerabilities: 2 high, 4 medium, 17 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103486 - Improper input validation
CWE-20 High
No
No
1.0.0.74 03.02.2025 SB2025020301
#VU100107 - Improper input validation
CWE-20 Medium
No
No
1.0.0.74 08.11.2024 SB2024110823
#VU100106 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Low
No
No
1.0.0.74 08.11.2024 SB2024110822
#VU100105 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
1.0.0.74 08.11.2024 SB2024110822
#VU94113 - Improper Access Control
CWE-284 Low
No
No
1.0.0.68 11.07.2024 SB2024071125
#VU94112 - Improper Authentication
CWE-287 Low
No
No
1.0.0.72 11.07.2024 SB2024071128
#VU94102 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
1.0.0.72 11.07.2024 SB2024071128
#VU94101 - Command injection
CWE-77 Low
No
No
1.0.0.72 11.07.2024 SB2024071128
#VU86735 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Low
No
No
1.0.0.72 22.02.2024 SB2024022232
#VU73748 - Command injection
CWE-77 Medium
No
No
1.0.0.64 16.03.2023 SB2023031619
#VU73743 - Command injection
CWE-77 Low
No
No
1.0.0.64 16.03.2023 SB2023031603
#VU73742 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
1.0.0.64 16.03.2023 SB2023031602
#VU73696 - Stack-based buffer overflow
CWE-121 Low
No
No
1.0.0.58 15.03.2023 SB2023031506
#VU70577 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Low
No
No
1.0.0.58 02.01.2023 SB2023010224
#VU70574 - Command injection
CWE-77 Low
No
No
1.0.0.58 02.01.2023 SB2023010221
#VU70563 - Improper input validation
CWE-20 Medium
No
No
1.0.0.64 02.01.2023 SB2023010208
#VU70561 - Memory corruption
CWE-119 Medium
No
No
1.0.0.64 02.01.2023 SB2023010206
#VU64827 - Command injection
CWE-77 Low
No
No
1.0.0.58 30.06.2022 SB2022063018
#VU64824 - Command injection
CWE-77 Low
No
No
1.0.0.58 30.06.2022 SB2022063017
#VU64822 - Command injection
CWE-77 Low
No
No
1.0.0.58 30.06.2022 SB2022063016


Showing elements 1 - 20 out of 23