CVE-2026-0410: Insufficient input validation in certain NETGEAR routers
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
netgear/r7000to a version that resolves this vulnerability.Fixed in V1.0.11.216 - Upgrade
Upgrade
netgear/rax20to a version that resolves this vulnerability.Fixed in V1.0.18.144 - Upgrade
Upgrade
netgear/rax35v2to a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax41to a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax41v2to a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/rax42to a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax42v2to a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/rax43to a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax43v2to a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/rax45to a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax49sto a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/rax50to a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax50sto a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
netgear/rax50v2to a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/rax54sv2to a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/rax54v2to a version that resolves this vulnerability.Fixed in V1.1.4.28 - Upgrade
Upgrade
netgear/raxe450to a version that resolves this vulnerability.Fixed in V1.2.14.114 - Upgrade
Upgrade
netgear/raxe500to a version that resolves this vulnerability.Fixed in V1.2.14.114 - Upgrade
Upgrade
netgear/xr1000to a version that resolves this vulnerability.Fixed in V1.1.0.22 - Upgrade
Upgrade
netgear/xr1000v2to a version that resolves this vulnerability.Fixed in V1.1.0.22 - Remove
Remove
netgear/r7000from your environment.Retire this End-of-Support device and replace with a newer NETGEAR device for continued security support.
- Remove
Remove
netgear/rax20from your environment.Retire this End-of-Support device and replace with a newer NETGEAR device for continued security support.
- Remove
Remove
netgear/rax41from your environment.Retire this End-of-Support device and replace with a newer NETGEAR device for continued security support.
- Remove
Remove
netgear/rax42from your environment.Retire this End-of-Support device and replace with a newer NETGEAR device for continued security support.
- Remove
Remove
netgear/rax43from your environment.Retire this End-of-Support device and replace with a newer NETGEAR device for continued security support.
- Remove
Remove
netgear/rax45from your environment.Retire this End-of-Support device and replace with a newer NETGEAR device for continued security support.
- Configuration
Enable automatic updates so devices will receive this patch automatically; if automatic updates cannot be enabled, check the firmware version and manually update to the fixed version listed for your model.
NETGEAR router firmware automatic_updates = enabled - Operational
Check the firmware version on each deployed device and update it to the fixed version listed for your model if it is not already applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0410?
CVE-2026-0410 has a low severity rating of 1.9.
What is CVE-2026-0410 about?
CVE-2026-0410 refers to insufficient input validation in certain NETGEAR routers that allows authenticated administrators to gain elevated access.
How do I fix CVE-2026-0410?
To fix CVE-2026-0410, ensure your router's firmware is updated to the latest version.
Who is affected by CVE-2026-0410?
Authenticated administrators connected to the local network are affected by CVE-2026-0410.
What type of vulnerability is CVE-2026-0410 categorized under?
CVE-2026-0410 is categorized under Input Validation vulnerabilities.