VendorsNETGEARrax38any version
Vulnerabilities

NETGEAR RAX38 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-27358
NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2021-45493
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.
Published 2021-12-26 · Modified
7.6EPSS 0.008
CVE-2021-38526
Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX35 before 1.0.3.94, RAX38 before 1.0.3.94, and RAX40 before 1.0.3.94.
Published 2021-08-11 · Modified
7.5EPSS 0.010
CVE-2021-41449
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
Published 2021-12-09 · Modified
7.1EPSS 0.016
CVE-2026-0420
Missing TLS certificate validation in NETGEAR's ReadyCloud client app
Published 2026-06-09 · Analyzed
5.9EPSS 0.001
CVE-2026-9216
Insufficient input validation vulnerability exists in certain NETGEAR RAX Models
Published 2026-09-08 · Analyzed
3.5EPSS 0.004