CVE-2026-0404
HIGHNETGEAR Orbi Firmware < 7.2.8.5 - Authenticated OS Command Injection via DHCPv6
Title source: llmDescription
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
References (13)
Core 13
Core References
Patch, Product patch
product
https://www.netgear.com/support/product/rbre960
Patch, Product product
patch
https://www.netgear.com/support/product/rbse960
Patch, Product product
patch
https://www.netgear.com/support/product/rbr850
Patch, Product product
patch
https://www.netgear.com/support/product/rbs850
Patch, Product product
patch
https://www.netgear.com/support/product/rbr860
Patch, Product product
patch
https://www.netgear.com/support/product/rbs860
Patch, Product product
patch
https://www.netgear.com/support/product/rbre950
Patch, Product product
patch
https://www.netgear.com/support/product/rbse950
Patch, Product product
patch
https://www.netgear.com/support/product/rbr750
Patch, Product product
patch
https://www.netgear.com/support/product/rbs750
Patch, Product product
patch
https://www.netgear.com/support/product/rbr840
Patch, Product product
patch
https://www.netgear.com/support/product/rbs840
Patch, Vendor Advisory vendor-advisory
https://kb.netgear.com/000070442/January-2026-NETGEAR-Security-Advisory
Scores
CVSS v3
8.0
EPSS
0.0018
EPSS Percentile
39.0%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
Status
published
Products (12)
netgear/rbr750_firmware
< 7.2.8.5
netgear/rbr840_firmware
< 7.2.8.5
netgear/rbr850_firmware
< 7.2.8.5
netgear/rbr860_firmware
< 7.2.8.5
netgear/rbre950_firmware
< 7.2.8.5
netgear/rbre960_firmware
< 7.2.8.5
netgear/rbs750_firmware
< 7.2.8.5
netgear/rbs840_firmware
< 7.2.8.5
netgear/rbs850_firmware
< 7.2.8.5
netgear/rbs860_firmware
< 7.2.8.5
... and 2 more
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026