CVE-2026-0410

LOW

Insufficient input validation in certain NETGEAR routers

Title source: cna
STIX 2.1

Description

Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.

Scores

CVSS v4 1.9
EPSS 0.0024
EPSS Percentile 14.4%
CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (20)
NETGEAR/R7000 < V1.0.11.216
NETGEAR/RAX20 < V1.0.18.144
NETGEAR/RAX35v2 < V1.0.16.132
NETGEAR/RAX41 < V1.0.16.132
NETGEAR/RAX41v2 < V1.1.4.28
NETGEAR/RAX42 < V1.0.16.132
NETGEAR/RAX42v2 < V1.1.4.28
NETGEAR/RAX43 < V1.0.16.132
NETGEAR/RAX43v2 < V1.1.4.28
NETGEAR/RAX45 < V1.0.16.132
... and 10 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026