CVE-2026-0414

MEDIUM

NETGEAR RBE97x - Arbitrary Code Execution Vulnerability Exists in RBE970

Title source: rule
STIX 2.1

Description

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

References (2)

Core 2

Scores

CVSS v4 4.3
EPSS 0.0019
EPSS Percentile 8.8%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
NETGEAR/RBE970 < V9.12.4.9
NETGEAR/RBE97x < V9.12.4.9
Published Jun 09, 2026
Tracked Since Jun 09, 2026