CVE-2026-0415

MEDIUM
4.5CVSS v3
CVSS v2
0.23% EPSS (exploit probability)
CWE-20CWE

Description

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected routers (1)

VendorModelMatched viaAffected versionsFixed inPatch Status
Netgear Netgear Orbi RBR850 versionEndExcluding=7.2.8.5 7.2.8.5 Patched

External references