Description
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting product's confidentiality or change certain configurations.
Problem types
CWE-306 Missing authentication for critical function
CWE-20 Improper input validation
Product status
Any version before V2.6.4.60
Any version before V2.7.6.8
Any version
Any version before V1.0.4.96
Any version before V1.0.6.46
Any version before V1.0.5.50
Any version before V1.0.5.50
Any version before V1.2.10.56
Any version before V1.2.10.56
Any version before V1.2.10.56
Any version before V1.0.5.50
Any version before V1.0.19.172
Any version before V1.0.19.172
Any version
Any version
Any version before V4.4.2.1
Any version
Any version
Any version
Any version
Any version before V4.4.2.1
Any version
Any version
Any version before V2.3.3.136
Any version before v2.3.3.136
Credits
ZeroZenx Labs
References
www.netgear.com/support/product/lbr20/
www.netgear.com/support/product/lbr1020/
www.netgear.com/support/product/r6700ax/
www.netgear.com/support/product/r9000/
www.netgear.com/support/product/r7800/
www.netgear.com/support/product/rax10/
www.netgear.com/support/product/rax120/
www.netgear.com/support/product/rax78/
www.netgear.com/support/product/rax120v2/
www.netgear.com/support/product/rax70/
www.netgear.com/support/product/rbr10/
www.netgear.com/support/product/rbr350/
www.netgear.com/support/product/rbr40/
www.netgear.com/support/product/rbr50/
www.netgear.com/support/product/rbs10/
www.netgear.com/support/product/rbs20/
www.netgear.com/support/product/rax36s/
www.netgear.com/support/product/rbr20/
www.netgear.com/support/product/rbs50/
www.netgear.com/support/product/rbs350/
www.netgear.com/support/product/xr500/
www.netgear.com/support/product/rbs40/
www.netgear.com/support/product/xr450/
kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory