CVE-2026-0404: Insufficient input validation in NETGEAR Orbi routers

Published Jan 13, 2026
·
Updated

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

Affected Software

25 affected components
Netgear Orbi
All of the following
Netgear RBR750 firmware<7.2.8.5
Netgear RBR750
All of the following
Netgear Rbr840 Firmware<7.2.8.5
Netgear RBR840
All of the following
Netgear Rbr850 Firmware<7.2.8.5
Netgear RBR850
All of the following
Netgear Rbr860 Firmware<7.2.8.5
Netgear Rbr860
All of the following
Netgear Rbs750 Firmware<7.2.8.5
Netgear RBS750
All of the following
Netgear Rbs840 Firmware<7.2.8.5
Netgear RBS840
All of the following
Netgear Rbs850 Firmware<7.2.8.5
Netgear RBS850
All of the following
Netgear Rbs860 Firmware<7.2.8.5
Netgear Rbs860
All of the following
Netgear Rbre950 Firmware<7.2.8.5
Netgear Rbre950
All of the following
Netgear Rbre960 Firmware<7.2.8.5
Netgear RBRE960
All of the following
Netgear Rbse950 Firmware<7.2.8.5
Netgear Rbse950
All of the following
Netgear Rbse960 Firmware<7.2.8.5
Netgear RBSE960

Remediation

Information

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: RBR750 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr750 RBR840 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr840 RBR850 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr850 RBR860 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr860 RBS750 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs750 RBS840 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs840 RBS850 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs850 RBS860 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs860 RBRE950 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbre950 RBRE960 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbre960 RBSE950 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbse950 RBSE960 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbse960

Event History

Jan 13, 2026
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0404?

CVE-2026-0404 is considered a high-severity vulnerability due to the potential for OS command injections.

2

How do I fix CVE-2026-0404?

To fix CVE-2026-0404, ensure that DHCPv6 is disabled on NETGEAR Orbi routers and apply any firmware updates provided by NETGEAR.

3

Who is affected by CVE-2026-0404?

CVE-2026-0404 affects users of NETGEAR Orbi routers with DHCPv6 functionality enabled.

4

What type of attacks can be performed using CVE-2026-0404?

Using CVE-2026-0404, authenticated attackers on the same network can execute OS command injections on the vulnerable router.

5

Is DHCPv6 enabled by default in NETGEAR Orbi devices concerning CVE-2026-0404?

No, DHCPv6 is not enabled by default in NETGEAR Orbi devices, which reduces the immediate risk for many users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203