CVE-2026-0403: Insufficient input validation in NETGEAR Orbi routers
Published Jan 13, 2026
·Updated
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.
Affected Software
21 affected components
Netgear Orbi
All of the following
Netgear Rbe971 Firmware<9.10.0.2
Netgear Rbe971
All of the following
Netgear Rbe970 Firmware<9.10.0.2
Netgear Rbe970
All of the following
Netgear RBR750 firmware<7.2.8.5
Netgear RBR750
All of the following
Netgear Rbr850 Firmware<7.2.8.5
Netgear RBR850
All of the following
Netgear Rbr860 Firmware<7.2.8.5
Netgear Rbr860
All of the following
Netgear Rbs750 Firmware<7.2.8.5
Netgear RBS750
All of the following
Netgear Rbs850 Firmware<7.2.8.5
Netgear RBS850
All of the following
Netgear Rbs860 Firmware<7.2.8.5
Netgear Rbs860
All of the following
Netgear Rbre960 Firmware<7.2.8.5
Netgear RBRE960
All of the following
Netgear Rbse960 Firmware<7.2.8.5
Netgear RBSE960
Remediation
Information
Devices with automatic updates enabled may already have this
patch applied. If not, please check the firmware version and update it to the
latest.
Fixed in:
RBE971 firmware 9.10.0.2 or later https://www.netgear.com/support/product/rbe971
RBE970 firmware 9.10.0.2 or later https://www.netgear.com/support/product/rbe970
RBR750 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbr750
RBR850 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbr850
RBR860 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbr860
RBS750 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbs750
RBS850 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbs850
RBS860 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbs860
RBRE960 firmware 7.2.7.15 or later https://www.netgear.com/support/product/rbre960
RBSE960 firmware 7.2.7.15 or later https://www.netgear.com/support/product/rbse960
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jan 13, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0403?
CVE-2026-0403 is classified as a high severity vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2026-0403?
To fix CVE-2026-0403, ensure that your NETGEAR Orbi router firmware is updated to the latest version released by NETGEAR.
3
Who is affected by CVE-2026-0403?
CVE-2026-0403 affects users of NETGEAR Orbi routers who have not implemented necessary mitigations.
4
What type of attack can exploit CVE-2026-0403?
CVE-2026-0403 can be exploited through OS command injection by attackers connected to the router's LAN.
5
Is there a workaround for CVE-2026-0403?
Currently, the best workaround for CVE-2026-0403 is to limit access to the router's LAN and apply all recommended security best practices.