CVE-2026-0418: Certain NETGEAR devices allow administrators to tamper with system
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CBR750 Orbi WiFi 6 DOCSIS 3.1 Mesh WiFi Cable Modem Routerto a version that resolves this vulnerability.Fixed in v4.6.14.4 - Upgrade
Upgrade
MR60 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.1.7.128 - Upgrade
Upgrade
MR70 Nighthawk Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.3.28 - Upgrade
Upgrade
MR80 Nighthawk Tri-band Mesh WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.1.7.6 - Upgrade
Upgrade
MS60 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.1.7.128 - Upgrade
Upgrade
MS70 Nighthawk Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.0.3.28 - Upgrade
Upgrade
MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satelliteto a version that resolves this vulnerability.Fixed in V1.1.7.6 - Upgrade
Upgrade
RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.11.112 - Upgrade
Upgrade
RAX38v2 Nighthawk AX4 4-Stream AX3000 WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.11.112 - Upgrade
Upgrade
RAX40v2 Nighthawk AX4 4-Stream WiFi Routerto a version that resolves this vulnerability.Fixed in V1.0.11.112 - Upgrade
Upgrade
RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.11.112 - Upgrade
Upgrade
RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.11.112 - Upgrade
Upgrade
RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Routerto a version that resolves this vulnerability.Fixed in V1.0.11.112 - Upgrade
Upgrade
RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.0.10.86 - Upgrade
Upgrade
RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V1.0.10.86 - Upgrade
Upgrade
RBR750 Orbi WiFi 6 Router AX4200to a version that resolves this vulnerability.Fixed in V4.6.14.3 - Upgrade
Upgrade
RBR850 Orbi WiFi 6 Router AX6000to a version that resolves this vulnerability.Fixed in V4.6.14.3 - Upgrade
Upgrade
RBRE960 Orbi Quad-band Mesh WiFi 6E Routerto a version that resolves this vulnerability.Fixed in V6.3.7.5 - Upgrade
Upgrade
RBS750 Orbi WiFi 6 Add-on Satellite AX4200to a version that resolves this vulnerability.Fixed in V4.6.14.3 - Upgrade
Upgrade
RBS850 Orbi WiFi 6 Satellite AX6000to a version that resolves this vulnerability.Fixed in V4.6.14.3 - Upgrade
Upgrade
RBSE960 Orbi Quad-band Mesh WiFi 6E Add-on Satelliteto a version that resolves this vulnerability.Fixed in V6.3.7.5 - Upgrade
Upgrade
RS700 Nighthawk BE19000 WiFi 7 Tri-Band Routerto a version that resolves this vulnerability.Fixed in V1.0.7.66 - Upgrade
Upgrade
XR1000 Nighthawk WiFi 6 Pro Gaming Routerto a version that resolves this vulnerability.Fixed in v1.0.0.68 - Remove
Remove
EX6120 AC1200 Dual Band WiFi Range Extenderfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
EX6130 AC1200 WiFi Range Extenderfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX15 4-Stream AX1800 WiFi 6 Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX20 4-Stream AX1800 WiFi 6 Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX200 Nighthawk Tri-Band AX12 12-Stream WiFi Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX42 Nighthawk AX5 5-Stream AX4200 WiFi Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX45 Nighthawk AX6 6-Stream AX4300 WiFi Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX75 Nighthawk AX8 8-Stream AX5700 WiFi 6 Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RAX80 Nighthawk AX8 8-Stream WiFi Routerfrom your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RBR840 Orbi WiFi 6 System AX5700from your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
- Remove
Remove
RBS840 Orbi WiFi 6 Add-on Satellite AX5700from your environment.NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0418?
The severity of CVE-2026-0418 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-0418?
To fix CVE-2026-0418, ensure your device's firmware is updated to the latest version or enable automatic updates.
What devices are affected by CVE-2026-0418?
CVE-2026-0418 affects certain NETGEAR devices that have insufficient configuration management.
What type of attack is possible with CVE-2026-0418?
Authenticated administrators connected to the local network can potentially tamper with the system due to CVE-2026-0418.
When was CVE-2026-0418 published?
CVE-2026-0418 was published on June 9, 2026.