Where
-Infinity
0
Severity
4.3
Input Validation
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

First published (updated )
Severity
4.3
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:D/RE:L/U:Amber

Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.

First published (updated )
Severity
4.3
Input Validation, Buffer Overflow
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.

First published (updated )
Severity
4.9
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:Amber

Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.

First published (updated )
Severity
8
EPSS
0.64%
Input Validation, Command Injection, OS Command Injection
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

Remedy

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: RBR750 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr750 RBR840 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr840 RBR850 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr850 RBR860 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbr860 RBS750 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs750 RBS840 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs840 RBS850 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs850 RBS860 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbs860 RBRE950 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbre950 RBRE960 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbre960 RBSE950 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbse950 RBSE960 firmware v7.2.8.5 or later https://www.netgear.com/support/product/rbse960
First published (updated )
Severity
7.8
EPSS
0.14%
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.

Remedy

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: CBR750 f irmware V4.6.14.8 or later https://www.netgear.com/support/product/cbr750 NBR750 firmware V4.6.15.14 or later https://www.netgear.com/support/product/nbr750 RBE370 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe370 RBE371 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe371 RBE372 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe372 RBE373 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe373 RBE374 firmware v12.1.3.11 or later https://www.netgear.com/support/product/rbe374 RBE770 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe770 RBE771 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe771 RBE772 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe772 RBE773 firmware v10.5.20.7 or later https://www.netgear.com/support/product/rbe773 RBE970  firmware v9.13.2.1 or later https://www.netgear.com/support/product/rbe970 RBE971 firmware v9.13.2.1 or later https://www.netgear.com/support/product/rbe971 RBR750 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr750 RBR840 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr840 RBR850 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr850 RBR860 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbr860 RBS750 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs750 RBS840 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs840 RBS850 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs850 RBS860 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbs860 RBRE950 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbre950 RBRE960 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbre960 RBSE950 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbse950 RBSE960 firmware v7.2.8.2 or later https://www.netgear.com/support/product/rbse960
First published (updated )
Severity
8
EPSS
0.06%
Input Validation
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

Remedy

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: RBE971 firmware 9.10.0.2 or later https://www.netgear.com/support/product/rbe971 RBE970 firmware 9.10.0.2 or later https://www.netgear.com/support/product/rbe970 RBR750 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbr750 RBR850 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbr850 RBR860 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbr860 RBS750 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbs750 RBS850 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbs850 RBS860 firmware 7.2.8.5 or later https://www.netgear.com/support/product/rbs860 RBRE960 firmware 7.2.7.15 or later https://www.netgear.com/support/product/rbre960 RBSE960 firmware 7.2.7.15 or later https://www.netgear.com/support/product/rbse960
First published (updated )
Severity
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Certain NETGEAR devices are affected by denial of service. This affects EX7500 before 1.0.0.72, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, RBRE960 before 6.0.3.68, RBSE960 before 6.0.3.68, RBR750 before 3.2.17.12, RBR850 before 3.2.17.12, RBS750 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, and RBK852 before 3.2.17.12.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203