CVE-2026-0415

MEDIUM

NETGEAR Orbi Routers - Authenticated Unauthorized Software Modification

Title source: manual
STIX 2.1

Description

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

Scores

CVSS v3 4.5
EPSS 0.0023
EPSS Percentile 13.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (27)
NETGEAR/RBE970 < V9.12.4.9
netgear/rbe970_firmware < 9.12.4.9
NETGEAR/RBE97x < V9.12.4.9
NETGEAR/RBR750 < V7.2.8.5
netgear/rbr750_firmware < 7.2.8.5
NETGEAR/RBR840 < V7.2.8.5
netgear/rbr840_firmware < 7.2.8.5
NETGEAR/RBR850 < V7.2.8.5
netgear/rbr850_firmware < 7.2.8.5
NETGEAR/RBR860 < V7.2.8.5
... and 17 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026