CVE Tools

Corega

12 CVEs tracked since 2015. Since Dec 2015, none of them reached CISA KEV.

Corega CVEs per month

Dec 2015 to Mar 2018. Point at a month, or focus the strip and use the arrow keys.
Corega CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-1230
2016-01null or fewer
2016-02null or fewer
2016-0310
2016-04null or fewer
2016-05null or fewer
2016-0630
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-0920
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-0330

Products

The products that kept showing up in Corega's monthly top three, with their CVEs summed over those months.

  1. Cg-wgr 1200 Firmware31 month
  2. Cg-wlbaragm Firmware22 months
  3. Wlr 300 Nm Firmware21 month
  4. Cg-wlbargl Firmware11 month
  5. Cg-wlbargmh Firmware11 month
  6. Cg-wlbargnl Firmware11 month
  7. Cg-wlbargs Firmware11 month
  8. Cg-wlncm4g Firmware11 month
  9. Cg-wlr300gnv Firmware11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Corega.

  1. CVE-2017-10853Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.8.8
  2. CVE-2017-10852Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.8.8
  3. CVE-2017-10854Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.8.8
  4. CVE-2017-10813CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.6.8
  5. CVE-2017-10814Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.6.8
  6. CVE-2016-7810Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.4.8
  7. CVE-2016-7809Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended ope...8.8
  8. CVE-2016-7811Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.8.8
  9. CVE-2016-7808Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.6.1
  10. CVE-2016-4822Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.8.0
  11. CVE-2016-4824The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attack...5.3
  12. CVE-2016-4823Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors.7.5
  13. CVE-2016-1158Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform admini...8.8
  14. CVE-2015-7792Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.9.8
  15. CVE-2015-7794Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.5.8

The record

Peak rank
#40 in Dec 2015
Busiest month shown
Dec 2015, 3 CVEs
Months with a KEV entry
0 since Dec 2015
Monthly snapshots
5 since 2015
Corega's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store