CVE-2026-0417: Insufficient input validation in certain NETGEAR routers
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected to the local network to tamper with the router's integrity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MR60 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.1.7.132 - Upgrade
Upgrade
MR70 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.3.28 - Upgrade
Upgrade
MR80 Nighthawk Tri-band Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.1.7.14 - Upgrade
Upgrade
MS60 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.1.7.132 - Upgrade
Upgrade
MS70 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.0.3.28 - Upgrade
Upgrade
MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.1.7.14 - Upgrade
Upgrade
RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.16.132 - Upgrade
Upgrade
RAX40v2 Nighthawk AX4 4-Stream WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.118 - Upgrade
Upgrade
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.120 - Upgrade
Upgrade
RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.12.120 - Upgrade
Upgrade
RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.0.10.86 - Upgrade
Upgrade
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.0.10.86 - Upgrade
Upgrade
XR1000 Nighthawk WiFi 6 Pro Gaming Routerto a version that resolves this vulnerability.Fixed in V1.0.0.68 - Remove
Remove
R6400v2 (EoS) AC1750 Smart WiFi Router 802.11ac Dual Band Gigabitfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R6700v3 (EoS) Nighthawk AC1750 Smart WiFi Dual Band Gigabit Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R6900P (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R7000 (EoS) Nighthawk AC1900 Smart WiFi Dual Band Gigabit Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R7000P (EoS) Nighthawk AC2300 Smart WiFi Dual Band Gigabit Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R7960P (EoS) Nighthawk X6S AC3600 Tri-Band WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R8000P (EoS) Nighthawk X6S AC4000 Tri Band WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
R8500 (EoS) Nighthawk X8 AC5300 Smart WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
RAX20 (EoS) 4-Stream AX1800 WiFi 6 Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
RAX41 (EoS) Nighthawk AX5 5-Stream AX3600 WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
RAX42 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
RAX43 (EoS) Nighthawk AX5 5-Stream AX4200 WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Remove
Remove
RAX45 (EoS) Nighthawk AX6 6-Stream AX4300 WiFi Routerfrom your environment.Retire this device and upgrade to a newer NETGEAR device for continued security support (model marked End-of-Support in advisory).
- Operational
Devices with automatic updates enabled may already have this patch applied. Check each device's firmware version and, if not already updated, apply the listed fixed firmware version for that model or update to the latest firmware from NETGEAR.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0417?
The severity of CVE-2026-0417 is medium with a CVSS score of 4.3.
What devices are affected by CVE-2026-0417?
CVE-2026-0417 affects certain NETGEAR routers, particularly the MR60, MR70, and MR80 models.
How do I fix CVE-2026-0417?
To fix CVE-2026-0417, check the firmware version of your NETGEAR router and update it to the latest version if necessary.
What does CVE-2026-0417 vulnerability allow?
CVE-2026-0417 allows authenticated administrators to tamper with the integrity of the router due to insufficient input validation.
Is automatic update safe for addressing CVE-2026-0417?
Yes, devices with automatic updates enabled may already have the patch for CVE-2026-0417 applied.