CVE-2026-0418: Certain NETGEAR devices allow administrators to tamper with system

Published Jun 9, 2026
·
Updated

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

Affected Software

70 affected components
All of the following
Netgear Cbr750 Firmware<4.6.14.4
Netgear CBR750
All of the following
Netgear Ex6120 Firmware
Netgear EX6120
All of the following
Netgear Ex6130 Firmware
Netgear EX6130
All of the following
Netgear Mr60 Firmware<1.1.7.128
Netgear MR60
All of the following
Netgear Mr70 Firmware<1.0.3.28
Netgear Mr70
All of the following
Netgear Mr80 Firmware<1.1.7.6
Netgear MR80
All of the following
Netgear Ms60 Firmware<1.1.7.128
Netgear MS60
All of the following
Netgear Ms70 Firmware<1.0.3.28
Netgear Ms70
All of the following
Netgear Ms80 Firmware<1.1.7.6
Netgear MS80
All of the following
Netgear Rax15 Firmware
Netgear RAX15
All of the following
Netgear Rax20 Firmware
Netgear RAX20
All of the following
Netgear Rax200 Firmware
Netgear RAX200
All of the following
Netgear Rax35v2 Firmware<1.0.11.112
Netgear RAX35v2
All of the following
Netgear Rax38v2 Firmware<1.0.11.112
Netgear Rax38v2
All of the following
Netgear Rax40v2 Firmware<1.0.11.112
Netgear RAX40v2
All of the following
Netgear Rax42 Firmware<1.0.11.112
Netgear RAX42
All of the following
Netgear Rax43 Firmware<1.0.11.112
Netgear RAX43
All of the following
Netgear Rax45 Firmware<1.0.11.112
Netgear RAX45
All of the following
Netgear Rax48 Firmware<1.0.11.112
Netgear Rax48
All of the following
Netgear Rax50 Firmware<1.0.11.112
Netgear RAX50
All of the following
Netgear Rax50s Firmware<1.0.11.112
Netgear Rax50s
All of the following
Netgear Rax75 Firmware
Netgear RAX75
All of the following
Netgear Rax80 Firmware
Netgear RAX80
All of the following
Netgear Raxe450 Firmware<1.0.10.86
Netgear RAXE450
All of the following
Netgear Raxe500 Firmware<1.0.10.86
Netgear RAXE500
All of the following
Netgear RBR750 firmware<4.6.14.3
Netgear RBR750
All of the following
Netgear Rbr840 Firmware<4.6.14.3
Netgear RBR840
All of the following
Netgear Rbr850 Firmware<4.6.14.3
Netgear RBR850
All of the following
Netgear Rbre960 Firmware<6.3.7.5
Netgear RBRE960
All of the following
Netgear Rbs750 Firmware<4.6.14.3
Netgear RBS750
All of the following
Netgear Rbs840 Firmware<4.6.14.3
Netgear RBS840
All of the following
Netgear Rbs850 Firmware<4.6.14.3
Netgear RBS850
All of the following
Netgear Rbse960 Firmware<6.3.7.5
Netgear RBSE960
All of the following
Netgear Rs700 Firmware<1.0.7.66
Netgear RS700
All of the following
Netgear Xr1000 Firmware<1.0.0.68
Netgear XR1000

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade CBR750 Orbi WiFi 6 DOCSIS 3.1 Mesh WiFi Cable Modem Router to a version that resolves this vulnerability.

    Fixed in v4.6.14.4
  2. Upgrade

    Upgrade MR60 Nighthawk Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.1.7.128
  3. Upgrade

    Upgrade MR70 Nighthawk Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.3.28
  4. Upgrade

    Upgrade MR80 Nighthawk Tri-band Mesh WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.1.7.6
  5. Upgrade

    Upgrade MS60 Nighthawk Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.1.7.128
  6. Upgrade

    Upgrade MS70 Nighthawk Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.0.3.28
  7. Upgrade

    Upgrade MS80 Nighthawk Tri-band Mesh WiFi 6 Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V1.1.7.6
  8. Upgrade

    Upgrade RAX35v2 Nighthawk AX4 4-Stream AX3000 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.112
  9. Upgrade

    Upgrade RAX38v2 Nighthawk AX4 4-Stream AX3000 WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.112
  10. Upgrade

    Upgrade RAX40v2 Nighthawk AX4 4-Stream WiFi Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.112
  11. Upgrade

    Upgrade RAX48 Nighthawk AX6 6-Stream AX5200 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.112
  12. Upgrade

    Upgrade RAX50 Nighthawk AX6 6-Stream AX5400 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.112
  13. Upgrade

    Upgrade RAX50S Nighthawk AX6 6-Stream AX5400 WiFi 6 Router to a version that resolves this vulnerability.

    Fixed in V1.0.11.112
  14. Upgrade

    Upgrade RAXE450 Nighthawk AXE10000 Tri-Band WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V1.0.10.86
  15. Upgrade

    Upgrade RAXE500 Nighthawk AX12 12-Stream AXE11000 Tri-Band WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V1.0.10.86
  16. Upgrade

    Upgrade RBR750 Orbi WiFi 6 Router AX4200 to a version that resolves this vulnerability.

    Fixed in V4.6.14.3
  17. Upgrade

    Upgrade RBR850 Orbi WiFi 6 Router AX6000 to a version that resolves this vulnerability.

    Fixed in V4.6.14.3
  18. Upgrade

    Upgrade RBRE960 Orbi Quad-band Mesh WiFi 6E Router to a version that resolves this vulnerability.

    Fixed in V6.3.7.5
  19. Upgrade

    Upgrade RBS750 Orbi WiFi 6 Add-on Satellite AX4200 to a version that resolves this vulnerability.

    Fixed in V4.6.14.3
  20. Upgrade

    Upgrade RBS850 Orbi WiFi 6 Satellite AX6000 to a version that resolves this vulnerability.

    Fixed in V4.6.14.3
  21. Upgrade

    Upgrade RBSE960 Orbi Quad-band Mesh WiFi 6E Add-on Satellite to a version that resolves this vulnerability.

    Fixed in V6.3.7.5
  22. Upgrade

    Upgrade RS700 Nighthawk BE19000 WiFi 7 Tri-Band Router to a version that resolves this vulnerability.

    Fixed in V1.0.7.66
  23. Upgrade

    Upgrade XR1000 Nighthawk WiFi 6 Pro Gaming Router to a version that resolves this vulnerability.

    Fixed in v1.0.0.68
  24. Remove

    Remove EX6120 AC1200 Dual Band WiFi Range Extender from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  25. Remove

    Remove EX6130 AC1200 WiFi Range Extender from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  26. Remove

    Remove RAX15 4-Stream AX1800 WiFi 6 Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  27. Remove

    Remove RAX20 4-Stream AX1800 WiFi 6 Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  28. Remove

    Remove RAX200 Nighthawk Tri-Band AX12 12-Stream WiFi Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  29. Remove

    Remove RAX42 Nighthawk AX5 5-Stream AX4200 WiFi Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  30. Remove

    Remove RAX43 Nighthawk AX5 5-Stream AX4200 WiFi Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  31. Remove

    Remove RAX45 Nighthawk AX6 6-Stream AX4300 WiFi Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  32. Remove

    Remove RAX75 Nighthawk AX8 8-Stream AX5700 WiFi 6 Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  33. Remove

    Remove RAX80 Nighthawk AX8 8-Stream WiFi Router from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  34. Remove

    Remove RBR840 Orbi WiFi 6 System AX5700 from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

  35. Remove

    Remove RBS840 Orbi WiFi 6 Add-on Satellite AX5700 from your environment.

    NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.

Event History

Jun 9, 2026
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-0418?

The severity of CVE-2026-0418 is medium with a CVSS score of 4.3.

2

How do I fix CVE-2026-0418?

To fix CVE-2026-0418, ensure your device's firmware is updated to the latest version or enable automatic updates.

3

What devices are affected by CVE-2026-0418?

CVE-2026-0418 affects certain NETGEAR devices that have insufficient configuration management.

4

What type of attack is possible with CVE-2026-0418?

Authenticated administrators connected to the local network can potentially tamper with the system due to CVE-2026-0418.

5

When was CVE-2026-0418 published?

CVE-2026-0418 was published on June 9, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203