Description
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent attackers authenticated over WiFi or on LAN to execute OS command injections on the router. DHCPv6 is not enabled by default.
Problem types
CWE-20 Improper Input Validation
Product status
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Any version before v7.2.8.5
Credits
Hyunseok Yun
References
www.netgear.com/support/product/rbre960
www.netgear.com/support/product/rbse960
www.netgear.com/support/product/rbr850
www.netgear.com/support/product/rbs850
www.netgear.com/support/product/rbr860
www.netgear.com/support/product/rbs860
www.netgear.com/support/product/rbre950
www.netgear.com/support/product/rbse950
www.netgear.com/support/product/rbr750
www.netgear.com/support/product/rbs750
www.netgear.com/support/product/rbr840
www.netgear.com/support/product/rbs840
kb.netgear.com/...442/January-2026-NETGEAR-Security-Advisory