CVE-2026-0404

HIGH

NETGEAR Orbi Firmware < 7.2.8.5 - Authenticated OS Command Injection via DHCPv6

Title source: llm
STIX 2.1

Description

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

References (13)

Core 13
Core References
Patch, Product product patch
https://www.netgear.com/support/product/rbr850
Patch, Product product patch
https://www.netgear.com/support/product/rbs850
Patch, Product product patch
https://www.netgear.com/support/product/rbr860
Patch, Product product patch
https://www.netgear.com/support/product/rbs860
Patch, Product product patch
https://www.netgear.com/support/product/rbr750
Patch, Product product patch
https://www.netgear.com/support/product/rbs750
Patch, Product product patch
https://www.netgear.com/support/product/rbr840
Patch, Product product patch
https://www.netgear.com/support/product/rbs840

Scores

CVSS v3 8.0
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (12)
netgear/rbr750_firmware < 7.2.8.5
netgear/rbr840_firmware < 7.2.8.5
netgear/rbr850_firmware < 7.2.8.5
netgear/rbr860_firmware < 7.2.8.5
netgear/rbre950_firmware < 7.2.8.5
netgear/rbre960_firmware < 7.2.8.5
netgear/rbs750_firmware < 7.2.8.5
netgear/rbs840_firmware < 7.2.8.5
netgear/rbs850_firmware < 7.2.8.5
netgear/rbs860_firmware < 7.2.8.5
... and 2 more
Published Jan 13, 2026
Tracked Since Feb 18, 2026