← Back

CVE-2026-0404

nvd nist
Published: Jan 13, 2026Modified: Feb 12, 2026

JSON object

Loading...
4.8
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Show more
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:AmberShow less
Source: a2826606-91e7-4eb6-899e-8484bd4575d5 (Secondary)

Description

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

Affected (12)

12 products
Rbr750 Firmware
Rbr840 Firmware
Rbr850 Firmware
Rbr860 Firmware
Rbs750 Firmware
Rbs840 Firmware
Rbs850 Firmware
Rbs860 Firmware
Rbre950 Firmware
Rbre960 Firmware
Rbse950 Firmware
Rbse960 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbr750
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbr840
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbr850
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbr860
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbs750
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbs840
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbs850
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbs860
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbre950
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbre960
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbse950
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 7.2.8.5
Running on/withPlatform Versions
Netgear
Rbse960
All versions

References (13)

Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchVendor Advisory
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
PatchProduct

Timeline

No history available yet.