CVE-2026-0416: Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionality
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intended management interface restrictions, resulting in unauthorized modification of protected router software or functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.2.14.114 - Upgrade
Upgrade
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.2.14.114 - Operational
Check firmware versions on affected devices and update to V1.2.14.114 if the patch is not already applied (devices with automatic updates may already have this patch).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0416?
The severity of CVE-2026-0416 is medium, with a CVSS score of 4.3.
How do I fix CVE-2026-0416?
To fix CVE-2026-0416, check the firmware version of your NETGEAR router and update it to the latest version if not already applied.
What type of vulnerability is CVE-2026-0416?
CVE-2026-0416 is an input validation vulnerability in certain NETGEAR routers.
Who is affected by CVE-2026-0416?
CVE-2026-0416 affects authenticated administrators with local network access to specific NETGEAR router models.
What can an attacker do with CVE-2026-0416?
An attacker can exploit CVE-2026-0416 to submit crafted input that bypasses management interface restrictions, leading to unauthorized modifications of protected router functionality.