CVE-2026-0418

MEDIUM

Certain NETGEAR devices allow administrators to tamper with system

Title source: cna
STIX 2.1

Description

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

References (36)

Core 36
Core References

Scores

CVSS v3 4.5
EPSS 0.0024
EPSS Percentile 15.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-15 CWE-610
Status published
Products (50)
NETGEAR/CBR750 < v4.6.14.4
netgear/cbr750_firmware < 4.6.14.4
NETGEAR/EX6120 < 1.0.0.72
netgear/ex6120_firmware
NETGEAR/EX6130 < 1.0.0.54
netgear/ex6130_firmware
NETGEAR/MR60 < V1.1.7.128
netgear/mr60_firmware < 1.1.7.128
NETGEAR/MR70 < V1.0.3.28
netgear/mr70_firmware < 1.0.3.28
... and 40 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026