CVE Tools

MS60 Firmware

39 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for MS60 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

MS60 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
MS60 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-063
2026-070
2026-083
2026-090

Severity

How the 39 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1436%
  • High1128%
  • Medium1333%
  • Low13%

Latest CVEs

The 15 most recently published vulnerabilities affecting MS60 Firmware.

  1. CVE-2026-11738Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.4.4
  2. CVE-2026-11739Command injection vulnerability in some NETGEAR Nighthawk devices6.4
  3. CVE-2026-11814Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers6.8
  4. CVE-2026-0418Certain NETGEAR devices allow administrators to tamper with system4.5
  5. CVE-2026-0417Insufficient input validation in certain NETGEAR routers4.5
  6. CVE-2026-9210Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router4.5
  7. CVE-2021-34983NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability6.5
  8. CVE-2021-34982NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability8.8
  9. CVE-2023-36187Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.9.8
  10. CVE-2022-27642This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this ...8.8
  11. CVE-2022-27647This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit...8.0
  12. CVE-2022-48322NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R700...9.8
  13. CVE-2022-48176Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.7.8
  14. CVE-2021-45539Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1.0.4.74, R8000P before 1.4.2.84, MR60 ...8.4
  15. CVE-2021-45540Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R7900 before 1.0.4.46, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R800...8.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store