CVE-2026-0415

Published Jun 9, 2026

Last updated 3 hours ago

Overview

Description
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
Source
a2826606-91e7-4eb6-899e-8484bd4575d5
NVD status
Analyzed
Products
rbe970_firmware, rbr750_firmware, rbr840_firmware, rbr850_firmware, rbr860_firmware, rbre950_firmware, rbre960_firmware, rbs750_firmware, rbs840_firmware, rbs850_firmware, rbs860_firmware, rbse950_firmware, rbse960_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
4.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
4.5
Impact score
3.6
Exploitability score
0.9
Vector string
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

a2826606-91e7-4eb6-899e-8484bd4575d5
CWE-20

Social media

Hype score
Not currently trending

Configurations