Home

Description

An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.

PUBLISHED Reserved 2025-12-03 | Published 2026-01-13 | Updated 2026-01-14 | Assigner NETGEAR




MEDIUM: 4.8CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Default status
unaffected

Any version before v7.2.8.5
affected

Credits

Hyunseok Yun finder

References

www.netgear.com/support/product/rbre960 patch product

www.netgear.com/support/product/rbse960 product patch

www.netgear.com/support/product/rbr850 product patch

www.netgear.com/support/product/rbs850 product patch

www.netgear.com/support/product/rbr860 product patch

www.netgear.com/support/product/rbs860 product patch

www.netgear.com/support/product/rbre950 product patch

www.netgear.com/support/product/rbse950 product patch

www.netgear.com/support/product/rbr750 product patch

www.netgear.com/support/product/rbs750 product patch

www.netgear.com/support/product/rbr840 product patch

www.netgear.com/support/product/rbs840 product patch

kb.netgear.com/...442/January-2026-NETGEAR-Security-Advisory vendor-advisory

cve.org (CVE-2026-0404)

nvd.nist.gov (CVE-2026-0404)

Download JSON