CVE-2026-0409
4.8
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: a2826606-91e7-4eb6-899e-8484bd4575d5 (Secondary)
Description
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrator performs certain specific management actions. This issue affects NETGEAR Orbi 370 series devices before V12.1.2.7.
Affected (4)
Products: Netgear: Rbe370 Firmware, Rbe371 Firmware, Rbe372 Firmware, Rbe374 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.1.2.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbe370 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.1.2.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbe371 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.1.2.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbe372 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.1.2.7 |
| Running on/with | Platform Versions |
|---|---|
Netgear Rbe374 | All versions |
References (2)
Source: a2826606-91e7-4eb6-899e-8484bd4575d5
Vendor Advisory
Timeline
No history available yet.