CVE-2026-0404
4.8
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:AmberShow more
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:AmberShow less
Source: a2826606-91e7-4eb6-899e-8484bd4575d5 (Secondary)
Description
An insufficient input validation vulnerability in NETGEAR Orbi devices'
DHCPv6 functionality allows network adjacent attackers authenticated
over WiFi or on LAN to execute OS command injections on the router.
DHCPv6 is not enabled by default.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr750 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr840 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr850 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbr860 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs750 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs840 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs850 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbs860 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbre950 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbre960 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbse950 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.2.8.5 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbse960 | All versions |
References (13)
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchVendor Advisory
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Timeline
No history available yet.