R7000
71 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for R7000, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
R7000 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 3 |
| 2026-07 | 0 |
| 2026-08 | 3 |
| 2026-09 | 0 |
Severity
How the 71 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical11
- High29
- Medium29
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting R7000.
- CVE-2026-9214Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device.4.5
- CVE-2026-11735Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models4.9
- CVE-2026-11738Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.4.4
- CVE-2026-0417Insufficient input validation in certain NETGEAR routers4.5
- CVE-2026-9210Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router4.5
- CVE-2026-0410Insufficient input validation in certain NETGEAR routers4.5
- CVE-2025-44650In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are conne...7.5
- CVE-2024-35520Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.8.4
- BDU:2024-05872Уязвимость микропрограммного обеспечения Wi-Fi роутеров NETGEAR R7000, связанная с переполнением буфера в стеке, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации7.9
- CVE-2021-34983NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability6.5
- CVE-2021-34982NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2024-1431Netgear R7000 Web Management Interface debuginfo.htm information disclosure4.3
- CVE-2024-1430Netgear R7000 Web Management Interface currentsetting.htm information disclosure4.3
- CVE-2023-31070Уязвимость модуля Efficient Multicast Forwarding (EMF) микропрограммного обеспечения маршрутизаторов TOTOLINK, TP-LINK, ASUS, Arris, Buffalo, D-Link, Linksys, Netgear, TRENDnet, Xiaomi, Linksys, Luxul, Phicomm, Ubee, позволяющая нарушителю выполнить произвольный код7.8
- CVE-2022-27642This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this ...8.8
Product grouping is registry-driven, with AI assist and human review. How it works