NETGEAR known exploited vulnerabilities
CISA lists 8 NETGEAR CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2022-09-08), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2016-6277 (Multiple Routers): EPSS 99.8%, added 2022-03-07
- CVE-2016-1555 (Wireless Access Point (WAP) Devices): EPSS 98.3%, added 2022-03-25
- CVE-2017-5521 (Multiple Devices): EPSS 89.2%, added 2022-09-08
- CVE-2016-10174 (WNR2000v5 Router): EPSS 83.3%, added 2022-03-25
- CVE-2017-6334 (DGN2200 Devices): EPSS 72.6%, added 2022-03-25
Most affected NETGEAR products
Multiple Devices (2), DGN2200 Devices (1), Wireless Access Point (WAP) Devices (1), WNR2000v5 Router (1), Wireless Router DGN2200 (1), Multiple Routers (1), JGS516PE Devices (1).
All NETGEAR CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2017-5521 | Multiple Devices | Multiple Devices Exposure of Sensitive Information | 2022-09-08 | 2022-09-29 | 89.2% | – |
| CVE-2017-6862 | Multiple Devices | Multiple Devices Buffer Overflow | 2022-06-08 | 2022-06-22 | 45.7% | – |
| CVE-2017-6334 | DGN2200 Devices | DGN2200 Devices OS Command Injection | 2022-03-25 | 2022-04-15 | 72.6% | – |
| CVE-2016-1555 | Wireless Access Point (WAP) Devices | Multiple WAP Devices Command Injection | 2022-03-25 | 2022-04-15 | 98.3% | – |
| CVE-2016-10174 | WNR2000v5 Router | WNR2000v5 Router Buffer Overflow | 2022-03-25 | 2022-04-15 | 83.3% | – |
| CVE-2017-6077 | Wireless Router DGN2200 | DGN2200 Remote Code Execution | 2022-03-07 | 2022-09-07 | 68.7% | – |
| CVE-2016-6277 | Multiple Routers | Multiple Routers Remote Code Execution | 2022-03-07 | 2022-09-07 | 99.8% | – |
| CVE-2020-26919 | JGS516PE Devices | Netgear JGS516PE Devices Missing Function Level Access Control | 2021-11-03 | 2022-05-03 | 57.5% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors