CVE-2026-0405: Authentication Bypass in NETGEAR Orbi Devices

Published Jan 13, 2026
·
Updated

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

Affected Software

51 affected components
Netgear Orbi
All of the following
Netgear Cbr750 Firmware<4.6.14.8
Netgear CBR750
All of the following
Netgear Nbr750 Firmware<4.6.15.14
Netgear Nbr750
All of the following
Netgear Rbe370 Firmware<12.1.3.11
Netgear Rbe370
All of the following
Netgear Rbe371 Firmware<12.1.3.11
Netgear Rbe371
All of the following
Netgear Rbe372 Firmware<12.1.3.11
Netgear Rbe372
All of the following
Netgear Rbe373 Firmware<12.1.3.11
Netgear Rbe373
All of the following
Netgear Rbe374 Firmware<12.1.3.11
Netgear Rbe374
All of the following
Netgear Rbe770 Firmware<10.5.20.7
Netgear Rbe770
All of the following
Netgear Rbe771 Firmware<10.5.20.7
Netgear Rbe771
All of the following
Netgear Rbe772 Firmware<10.5.20.7
Netgear Rbe772
All of the following
Netgear Rbe773 Firmware<10.5.20.7
Netgear Rbe773
All of the following
Netgear Rbe970 Firmware<9.13.2.1
Netgear Rbe970
All of the following
Netgear Rbe971 Firmware<9.13.2.1
Netgear Rbe971
All of the following
Netgear RBR750 firmware<7.2.8.2
Netgear RBR750
All of the following
Netgear Rbr840 Firmware<7.2.8.2
Netgear RBR840
All of the following
Netgear Rbr850 Firmware<7.2.8.2
Netgear RBR850
All of the following
Netgear Rbr860 Firmware<7.2.8.2
Netgear Rbr860
All of the following
Netgear Rbs750 Firmware<7.2.8.2
Netgear RBS750
All of the following
Netgear Rbs840 Firmware<7.2.8.2
Netgear RBS840
All of the following
Netgear Rbs850 Firmware<7.2.8.2
Netgear RBS850
All of the following
Netgear Rbs860 Firmware<7.2.8.2
Netgear Rbs860
All of the following
Netgear Rbre950 Firmware<7.2.8.2
Netgear Rbre950
All of the following
Netgear Rbre960 Firmware<7.2.8.2
Netgear RBRE960
All of the following
Netgear Rbse950 Firmware<7.2.8.2
Netgear Rbse950
All of the following
Netgear Rbse960 Firmware<7.2.8.2
Netgear RBSE960

Remediation

Information

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: CBR750 f irmware V4.6.14.8 or later https://www.netgear.com/support/product/cbr750 NBR750 firmware V4.6.15.14 or later https://www.netgear.com/support/product/nbr750 RBE370 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe370 RBE371 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe371 RBE372 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe372 RBE373 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe373 RBE374 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe374 RBE770 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe770 RBE771 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe771 RBE772 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe772 RBE773 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe773 RBE970  firmware v9.13.2.1 or later https://www.netgear.com/support/product/rbe970 RBE971 firmware v9.13.2.1 or later https://www.netgear.com/support/product/rbe971 RBR750 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr750 RBR840 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr840 RBR850 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr850 RBR860 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr860 RBS750 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs750 RBS840 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs840 RBS850 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs850 RBS860 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs860 RBRE950 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbre950 RBRE960 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbre960 RBSE950 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbse950 RBSE960 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbse960

Event History

Jan 13, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0405?

CVE-2026-0405 is considered a high severity vulnerability due to its potential for unauthorized administrative access.

2

How do I fix CVE-2026-0405?

To fix CVE-2026-0405, update your NETGEAR Orbi device to the latest firmware version provided by NETGEAR.

3

Who is affected by CVE-2026-0405?

CVE-2026-0405 affects users of NETGEAR Orbi devices connected to the local network.

4

What impact does CVE-2026-0405 have on user security?

CVE-2026-0405 allows local network users to gain unauthorized access to the router's web interface, potentially compromising the network's security.

5

Is CVE-2026-0405 being exploited in the wild?

As of now, there have been no confirmed reports of CVE-2026-0405 being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203