VendorsNETGEARxr300_firmware1.0.3.38
Vulnerabilities

NETGEAR xr300 Firmware 1.0.3.38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-52080
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the share_name parameter.
Published 2025-07-15 · Analyzed
6.5EPSS 0.003
CVE-2025-52081
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the usb_folder parameter.
Published 2025-07-15 · Analyzed
6.5EPSS 0.003
CVE-2025-52082
In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing the read_access parameter.
Published 2025-07-15 · Analyzed
6.5EPSS 0.003