CVE-2026-0411

HIGH

NETGEAR Orbi Satellites - Administrator Access Information Disclosure

Title source: manual
STIX 2.1

Description

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.

Scores

CVSS v3 8.0
EPSS 0.0028
EPSS Percentile 20.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (11)
NETGEAR/RBE970 < 6.3.8.11
netgear/rbe970_firmware < 9.13.2.1
NETGEAR/RBE97x < 6.3.8.11
NETGEAR/RBR350 < V4.4.2.2
netgear/rbr350_firmware < 4.4.2.2
NETGEAR/RBR760 < V6.3.8.11
netgear/rbr760_firmware < 6.3.8.11
NETGEAR/RBS350 < V4.4.2.2
netgear/rbs350_firmware < 4.4.2.2
NETGEAR/RBS760 < V6.3.8.11
... and 1 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026