CVE-2026-0417: Insufficient input validation in certain NETGEAR routers

Published Jun 9, 2026
·
Updated

Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.

Affected Software

54 affected components
All of the following
Netgear Mr60 Firmware<1.1.7.132
Netgear MR60
All of the following
Netgear Mr70 Firmware<1.0.3.28
Netgear Mr70
All of the following
Netgear Mr80 Firmware<1.1.7.14
Netgear MR80
All of the following
Netgear Ms60 Firmware<1.1.7.132
Netgear MS60
All of the following
Netgear Ms70 Firmware<1.0.3.28
Netgear Ms70
All of the following
Netgear Ms80 Firmware<1.1.7.14
Netgear MS80
All of the following
Netgear R6400v2 Firmware<1.0.4.128
Netgear R6400v2
All of the following
Netgear R6700v3 Firmware<1.0.4.128
Netgear R6700v3
All of the following
Netgear R6900p Firmware<1.3.3.152
Netgear R6900P
All of the following
Netgear R7000 Firmware<1.0.11.216
Netgear R7000
All of the following
Netgear R7000p Firmware<1.3.3.152
Netgear R7000P
All of the following
Netgear R7960p Firmware<1.4.4.92
Netgear R7960P
All of the following
Netgear R8000p Firmware<1.4.4.92
Netgear R8000P
All of the following
Netgear R8500 Firmware
Netgear R8500
All of the following
Netgear Rax20 Firmware<1.0.18.144
Netgear RAX20
All of the following
Netgear Rax35v2 Firmware<1.0.16.132
Netgear RAX35v2
All of the following
Netgear Rax40v2 Firmware<1.0.12.118
Netgear RAX40v2
All of the following
Netgear Rax41 Firmware<1.0.12.118
Netgear RAX41
All of the following
Netgear Rax42 Firmware<1.0.12.118
Netgear RAX42
All of the following
Netgear Rax43 Firmware<1.0.12.120
Netgear RAX43
All of the following
Netgear Rax45 Firmware<1.0.12.118
Netgear RAX45
All of the following
Netgear Rax48 Firmware<1.0.12.118
Netgear Rax48
All of the following
Netgear Rax50 Firmware<1.0.12.120
Netgear RAX50
All of the following
Netgear Rax50s Firmware<1.0.12.120
Netgear Rax50s
All of the following
Netgear Raxe450 Firmware<1.0.10.86
Netgear RAXE450
All of the following
Netgear Raxe500 Firmware<1.0.10.86
Netgear RAXE500
All of the following
Netgear Xr1000 Firmware<1.0.0.68
Netgear XR1000

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MR60 Nighthawk Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.1.7.132
  2. Upgrade

    Upgrade MR70 Nighthawk Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.3.28
  3. Upgrade

    Upgrade MR80 Nighthawk Tri-band Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.1.7.14
  4. Upgrade

    Upgrade MS60 Nighthawk Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.1.7.132
  5. Upgrade

    Upgrade MS70 Nighthawk Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.0.3.28
  6. Upgrade

    Upgrade MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.1.7.14
  7. Upgrade

    Upgrade RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.16.132
  8. Upgrade

    Upgrade RAX40v2 Nighthawk AX4 4-Stream WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  9. Upgrade

    Upgrade RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.118
  10. Upgrade

    Upgrade RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.120
  11. Upgrade

    Upgrade RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.12.120
  12. Upgrade

    Upgrade RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V1.0.10.86
  13. Upgrade

    Upgrade RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V1.0.10.86
  14. Upgrade

    Upgrade XR1000 Nighthawk WiFi 6 Pro Gaming Router to a version that resolves this vulnerability.

    Fixed in V1.0.0.68
  15. Remove

    Remove R6400v2 (EoS) AC1750 Smart WiFi Router 802.11ac Dual Band Gigabit from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  16. Remove

    Remove R6700v3 (EoS) Nighthawk AC1750 Smart WiFi Dual Band Gigabit Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  17. Remove

    Remove R6900P (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  18. Remove

    Remove R7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  19. Remove

    Remove R7000P (EoS) Nighthawk AC2300 Smart WiFi Dual Band Gigabit Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  20. Remove

    Remove R7960P (EoS) Nighthawk X6S AC3600 Tri-Band WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  21. Remove

    Remove R8000P (EoS) Nighthawk X6S AC4000 Tri Band WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  22. Remove

    Remove R8500 (EoS) Nighthawk X8 AC5300 Smart WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  23. Remove

    Remove RAX20 (EoS) 4-Stream AX1800 WiFi 6 Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  24. Remove

    Remove RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  25. Remove

    Remove RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  26. Remove

    Remove RAX43 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  27. Remove

    Remove RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Router from your environment.

    Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).

  28. Operational

    Devices with automatic updates enabled may already have this patch applied. Check each device's firmware version and, if not already updated, apply the listed fixed firmware version for that model or update to the latest firmware from NETGEAR.

Event History

Jun 9, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0417?

The severity of CVE-2026-0417 is medium with a CVSS score of 4.3.

2

What devices are affected by CVE-2026-0417?

CVE-2026-0417 affects certain NETGEAR routers, particularly the MR60, MR70, and MR80 models.

3

How do I fix CVE-2026-0417?

To fix CVE-2026-0417, check the firmware version of your NETGEAR router and update it to the latest version if necessary.

4

What does CVE-2026-0417 vulnerability allow?

CVE-2026-0417 allows authenticated administrators to tamper with the integrity of the router due to insufficient input validation.

5

Is automatic update safe for addressing CVE-2026-0417?

Yes, devices with automatic updates enabled may already have the patch for CVE-2026-0417 applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203