CVE-2026-0415
MEDIUM4.5CVSS v3
—CVSS v2
0.23%
EPSS (exploit probability)
CWE-20CWE
Description
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected routers (1)
| Vendor | Model | Matched via | Affected versions | Fixed in | Patch Status |
|---|---|---|---|---|---|
| Netgear | Netgear Orbi RBR850 | — |
versionEndExcluding=7.2.8.5 | 7.2.8.5 | Patched |